CVE-2015-5520

Orchard <1.9.1 - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.

Exploits (1)

exploitdb WRITEUP
by Paris Zoumpouloglou · textwebappsasp
https://www.exploit-db.com/exploits/37533

References (5)

Core 5

Scores

EPSS 0.1581
EPSS Percentile 94.8%

Details

CWE
CWE-79
Status published
Products (5)
orchardproject/orchard 1.7.3
orchardproject/orchard 1.8
orchardproject/orchard 1.8.1
orchardproject/orchard 1.8.2
orchardproject/orchard 1.9
Published Jul 14, 2015
Tracked Since Feb 18, 2026