PT-2022-24048 · Orchardproject · Orchard Cms

Bruno Barreirinhas

·

Published

2022-11-25

·

Updated

2025-04-25

·

CVE-2022-37720

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orchardproject Orchard CMS version 1.10.3
Description The issue allows a low-privileged user, such as an author or publisher, to inject crafted HTML and JavaScript payload in a blog post. This leads to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.
Recommendations For Orchardproject Orchard CMS version 1.10.3, update to a version that fixes the Cross Site Scripting (XSS) issue to prevent admin account takeover or privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-37720

Affected Products

Orchard Cms