Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gg9-gwj4-mqmj

Опубликовано: 04 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

OrchardCore vulnerable to HTML injection

OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch.

Пакеты

Наименование

OrchardCore

nuget
Затронутые версииВерсия исправления

>= 1.0.0-rc1-11259, < 1.4.0

1.4.0

EPSS

Процентиль: 42%
0.002
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.

EPSS

Процентиль: 42%
0.002
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79