Umbraco before version 7.4.0 contains a server-side request forgery vulnerability in feedproxy.aspx that allows attackers to send arbitrary HTTP GET requests via http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:80/index.
View the template here CVE-2015-8813.yaml
References:
https://blog.securelayer7.net/umbraco-the-open-source-asp-net-cms-multiple-vulnerabilities/