CVE-2020-37019

MEDIUM

Orchard Core RC1 - XSS

Title source: llm
STIX 2.1

Description

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.

Exploits (1)

exploitdb WORKING POC
by SunCSR · textwebappsaspx
https://www.exploit-db.com/exploits/48456

Scores

CVSS v3 6.4
EPSS 0.0011
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jan 30, 2026
Tracked Since Feb 18, 2026