CVE-2015-8813: SSRF
The PageLoad function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
Other sources
The PageLoad function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8813?
CVE-2015-8813 is classified as a high severity vulnerability that allows remote attackers to execute arbitrary code.
How do I fix CVE-2015-8813?
To fix CVE-2015-8813, upgrade Umbraco CMS to version 7.4.0 or later.
What versions of Umbraco are affected by CVE-2015-8813?
Umbraco CMS versions prior to 7.4.0, specifically up to and including 7.3.8, are affected by CVE-2015-8813.
What type of attacks can exploit CVE-2015-8813?
CVE-2015-8813 can be exploited by remote attackers to perform unauthorized actions or execute malicious code on the server.
Is CVE-2015-8813 present in any specific Umbraco components?
CVE-2015-8813 specifically affects the 'FeedProxy.aspx.cs' file within the Umbraco Web component.