Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h66j-xm43-47pp

Опубликовано: 15 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Umbraco CMS contains a server-side request forgery vulnerability

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

Пакеты

Наименование

UmbracoCms

nuget
Затронутые версииВерсия исправления

= 8.14.1

Отсутствует

EPSS

Процентиль: 9%
0.00032
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.3
nvd
23 дня назад

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

EPSS

Процентиль: 9%
0.00032
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-918