Description
Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
SunCSR (Sun* Cyber Security Research)
References
www.exploit-db.com/exploits/48456 (ExploitDB-48456)
www.orchardcore.net/ (Orchard Core Official Website)
github.com/OrchardCMS/OrchardCore (Orchard Core GitHub Repository)
github.com/OrchardCMS/OrchardCore/issues/5802 (GitHub Issue #5802)
www.vulncheck.com/...core-rc-persistent-cross-site-scripting (VulnCheck Advisory: Orchard Core RC1 - Persistent Cross-Site Scripting)