4.3
CVSSv2

CVE-2015-5520

Published: 14/07/2015 Updated: 17/07/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 up to and including 1.8.2 and 1.9.x prior to 1.9.1 allows remote malicious users to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.

Vulnerable Product Search on Vulmon Subscribe to Product

orchardproject orchard 1.8

orchardproject orchard 1.8.1

orchardproject orchard 1.8.2

orchardproject orchard 1.9

orchardproject orchard 1.7.3

Exploits

----------------- Background ----------------- Orchard is a free, open source, community-focused content management system written in ASPNET platform using the ASPNET MVC framework Its vision is to create shared components for building ASPNET applications and extensions, and specific applications that leverage these components to meet the need ...