vendor:
Orchard CMS
by:
Paris Zoumpouloglou
8.8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: Orchard CMS
Affected Version From: 1.7.2003
Affected Version To: 1.9.2000
Patch Exists: YES
Related CWE: N/A
CPE: orchardcms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Persistent XSS Vulnerability in Orchard CMS
A persistent XSS vulnerability was discovered in the Users module that is distributed with the core distribution of the CMS. The issue potentially allows elevation of privileges by tricking an administrator to execute some custom crafted script on his behalf. The issue affects the Username field, since a user is allowed to register a username containing potentially dangerous characters.
Mitigation:
See http://docs.orchardproject.net/Documentation/Patch-20150630