vendor:
Orchard Core
by:
SunCSR (Sun* Cyber Security Research)
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Orchard Core
Affected Version From: RC1
Affected Version To: RC1
Patch Exists: YES
Related CWE: N/A
CPE: a:orchardcms:orchard_core
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Orchard Core RC1 – Persistent Cross-Site Scripting
Persistent Cross-site scripting (Stored XSS) vulnerabilities in Orchard CMS - Orchard Core RC1 allow remote attackers to inject arbitrary web script or HTML via create or edit blog content.
Mitigation:
Upgrade to the latest version of Orchard Core RC2