CVE-2017-15280

XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:14

Type Values Removed Values Added
References () http://issues.umbraco.org/issue/U4-10506 - Issue Tracking, Patch, Vendor Advisory () http://issues.umbraco.org/issue/U4-10506 - Issue Tracking, Patch, Vendor Advisory
References () https://github.com/umbraco/Umbraco-CMS/commit/5dde2efe0d2b3a47d17439e03acabb7ea2befb64 - Patch, Third Party Advisory () https://github.com/umbraco/Umbraco-CMS/commit/5dde2efe0d2b3a47d17439e03acabb7ea2befb64 - Patch, Third Party Advisory

Information

Published : 2017-10-12 08:29

Updated : 2024-11-21 03:14


NVD link : CVE-2017-15280

Mitre link : CVE-2017-15280

CVE.ORG link : CVE-2017-15280


JSON object : View

Products Affected

umbraco

  • umbraco_cms
CWE
CWE-611

Improper Restriction of XML External Entity Reference