PoC Index

CVE-2015-8813

HIGH 8.2EPSS 11.2%

The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
CVSS v3.0
8.2 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
11.15% chance of exploitation in the next 30 days, 96th percentile
Nuclei
high · CWE-918
Published
2017-03-03
Updated
2024-08-06

Nuclei templates (1)

References

Related