CVE-2021-47776

Source
https://cve.org/CVERecord?id=CVE-2021-47776
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47776.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-47776
Aliases
Published
2026-01-15T16:16:09.510Z
Modified
2026-04-10T04:41:06.244688Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.14.1"
        }
    ]
}

Affected versions

4.*
4.7.2
Release-4.*
Release-4.5.2
Release-4.6.0
Other
Sprint-Juno-A
release-6.*
release-6.1.0-beta
release-7.*
release-7.0.0
release-7.0.0-RC
release-7.0.0-beta
release-7.1.0
release-7.1.0-RC
release-7.1.1
release-7.1.2
release-7.1.3
release-7.1.4
release-7.2.0-alpha
release-7.2.0-beta
release-7.2.0-beta2
release-8.*
release-8.1.0
release-8.10.0-rc
release-8.14.0
release-8.14.0-rc
release-8.14.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47776.json"