Back

CRITICAL

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS)

Published Nov 25, 2022

Description

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 25, 2022
Updated Jul 9, 2026
Reserved Aug 8, 2022
CISA Vulnrichment
Updated Apr 25, 2025
NVD
Status Modified
Modified Jul 9, 2026
Red Hat
Severity n/a
Public date n/a