CVE-2021-47776

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:umbraco:umbraco_cms:8.14.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-15 16:16

Updated : 2026-01-23 18:06


NVD link : CVE-2021-47776

Mitre link : CVE-2021-47776

CVE.ORG link : CVE-2021-47776


JSON object : View

Products Affected

umbraco

  • umbraco_cms
CWE
CWE-918

Server-Side Request Forgery (SSRF)