Description
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.
In plain language
AI Worth attentionIf you run Umbraco CMS versions earlier than 7.4.0, an attacker may be able to trick your server into making requests to other systems (SSRF). Most small businesses should update to 7.4.0 if this feature is reachable from the internet.
In Umbraco CMS before 7.4.0, the Page_Load handler for FeedProxy.aspx.cs uses a user-controlled url parameter to fetch remote content, enabling server-side request forgery (SSRF) that can reach internal network resources.
What to do now
- Check your Umbraco CMS version number and confirm it is earlier than 7.4.0.
- If you are on a vulnerable version, upgrade Umbraco CMS to 7.4.0 (or later).
- After upgrading, verify that the Umbraco site still loads normally and that any affected admin/dashboard functions behave as expected.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-8813 and every CVE in our database. Create a free account — no credit card required.
Create Free Account