Sébastien Ros

6 exploits Active since Jan 2022
CVE-2022-0243 WRITEUP MEDIUM WRITEUP
NuGet OrchardCore.Application.Cms.Targets <1.2.2 - XSS
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
CVSS 5.4
CVE-2022-0274 WRITEUP MEDIUM WRITEUP
NuGet OrchardCore.Application.Cms.Targets <1.2.2 - XSS
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
CVSS 5.4
CVE-2022-0820 WRITEUP MEDIUM WRITEUP
OrchardCore < 1.3.0 - Stored Cross-Site Scripting
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVSS 6.1
CVE-2022-0821 WRITEUP MEDIUM WRITEUP
OrchardCore < 1.3.0 - Improper Authorization
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVSS 6.5
CVE-2022-0822 WRITEUP MEDIUM WRITEUP
OrchardCore < 1.3.0 - Reflected Cross-Site Scripting
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVSS 5.4
CVE-2022-32173 WRITEUP MEDIUM WRITEUP
OrchardCore 1.0.0-rc1-11259-1.2.2 - Authenticated HTML Injection in Dashboard
In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.
CVSS 5.4