XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-10-12T08:00:00

Updated: 2017-10-12T07:57:01

Reserved: 2017-10-11T00:00:00


Link: CVE-2017-15280

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-10-12T08:29:00.510

Modified: 2017-10-25T12:53:37.937


Link: CVE-2017-15280

JSON object: View

cve-icon Redhat Information

No data.

CWE