First published: Thu Oct 12 2017(Updated: )
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to `Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs`.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/UmbracoCms.Web | <7.7.3 | 7.7.3 |
Umbraco CMS | <=7.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15280 has a medium severity level due to its potential for sensitive information exposure.
To fix CVE-2017-15280, upgrade Umbraco CMS to version 7.7.3 or later.
CVE-2017-15280 is an XML external entity (XXE) vulnerability allowing attackers to access sensitive files or conduct server-side request forgery (SSRF).
CVE-2017-15280 affects Umbraco CMS versions prior to 7.7.3.
Yes, CVE-2017-15280 can lead to data breaches by allowing unauthorized access to sensitive information on the server.