CVE-2021-47776: Umbraco v8.14.1 - 'baseUrl' SSRF
Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47776?
CVE-2021-47776 is classified as a high severity vulnerability due to its potential for server-side request forgery exploits.
How do I fix CVE-2021-47776?
To fix CVE-2021-47776, you should upgrade to Umbraco CMS version 8.14.2 or later.
What does CVE-2021-47776 affect?
CVE-2021-47776 affects Umbraco CMS version 8.14.1, allowing unauthorized access through manipulated baseUrl parameters.
What type of vulnerability is CVE-2021-47776?
CVE-2021-47776 is a server-side request forgery (SSRF) vulnerability.
Can CVE-2021-47776 lead to data exposure?
Yes, CVE-2021-47776 can lead to unauthorized access and data exposure by manipulating server requests.