CVE-2017-15280

XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-10-12 08:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-15280

Mitre link : CVE-2017-15280

CVE.ORG link : CVE-2017-15280


JSON object : View

Products Affected

umbraco

  • umbraco_cms
CWE
CWE-611

Improper Restriction of XML External Entity Reference