CVE-2015-8813
HIGH 8.2EPSS 11.2%
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
- CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N - CVSS v3.0
- 8.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 11.15% chance of exploitation in the next 30 days, 96th percentile
- Nuclei
- high · CWE-918
- Published
- 2017-03-03
- Updated
- 2024-08-06