Alexandr Chernyaev

1 exploit Active since Oct 2020
CVE-2020-15263 WRITEUP HIGH WRITEUP
Orchid Platform 9.0.0-9.4.3 - Cross-Site Scripting via Inline Attribute Injection
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.
CVSS 8.0