XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4046 | XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs. |
Github GHSA |
GHSA-h2vq-7gf2-qw9v | Umbraco CMS XXE Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:50:16.479Z
Reserved: 2017-10-11T00:00:00
Link: CVE-2017-15280
No data.
Status : Deferred
Published: 2017-10-12T08:29:00.510
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15280
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA