Описание
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
Ссылки
- Issue Tracking
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- PatchVendor Advisory
- Issue Tracking
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.3.8 (включая)
cpe:2.3:a:umbraco:umbraco:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.83448
Высокий
8.2 High
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-918
Связанные уязвимости
EPSS
Процентиль: 99%
0.83448
Высокий
8.2 High
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-918