GHSA-h2vq-7gf2-qw9v
Dashboard / Vulnerabilities / GHSA-h2vq-7gf2-qw9v
Summary: Umbraco CMS XXE Vulnerability
Details: XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to `Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs`.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-15280, https://github.com/umbraco/Umbraco-CMS/commit/5dde2efe0d2b3a47d17439e03acabb7ea2befb64, https://github.com/umbraco/Umbraco-CMS, https://github.com/umbraco/Umbraco-CMS/blob/release-7.7.3/src/Umbraco.Web/Umbraco.Web.csproj, http://issues.umbraco.org/issue/U4-10506
Affected packages
Package
Name: UmbracoCms.Web
Purl: pkg:nuget/UmbracoCms.Web
Affected ranges
Type: ECOSYSTEM
Events:
