5.5
CVSSv3

CVE-2017-15280

Published: 12/10/2017 Updated: 25/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

XML external entity (XXE) vulnerability in Umbraco CMS prior to 7.7.3 allows malicious users to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.

Vulnerable Product Search on Vulmon Subscribe to Product

umbraco umbraco cms