OrchardCore vulnerable to HTML injection
Moderate severity
GitHub Reviewed
Published
Oct 4, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Oct 3, 2022
Published to the GitHub Advisory Database
Oct 4, 2022
Reviewed
Oct 4, 2022
Last updated
Jan 27, 2023
OrchardCore versions starting with 1.0.0-rc1-11259 and prior to 1.4.0 are vulnerable to HTML injection. The vulnerability allows an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users. Version 1.4.0 contains a patch.
References