CVE-2021-47776

MEDIUM

Umbraco Cms - SSRF

Title source: rule

Description

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

Exploits (1)

exploitdb WORKING POC
by NgoAnhDuc · textwebappsaspx
https://www.exploit-db.com/exploits/50462

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-918
Status published
Products (3)
nuget/UmbracoCms NuGet
umbraco/Umbraco 8.14.1
umbraco/umbraco_cms 8.14.1
Published Jan 15, 2026
Tracked Since Feb 18, 2026