Improper Authorization in orchardcms/orchardcore
Feb 24th 2022
A low-privilege user (I tested it with
Editor priv user) can create any
role in the application.
Proof of Concept
Make a POST request to
/Admin/Roles/Create using low-priv user's
A new role will be created with the specified name.
A low-priv user can create a number of roles which breaks the authorization principle of this application.
We are processing your report and will contact the orchardcms/orchardcore team within 24 hours. a year ago
We have contacted a member of the orchardcms/orchardcore team and are waiting to hear back a year ago
We have sent a follow up to the orchardcms/orchardcore team. We will try again in 7 days. a year ago
A orchardcms/orchardcore maintainer validated this vulnerability a year ago
Rohan Sharma has been awarded the disclosure bounty
The fix bounty is now up for grabs
We have sent a fix follow up to the orchardcms/orchardcore team. We will try again in 7 days. a year ago
A orchardcms/orchardcore maintainer marked this as fixed in 1.3.0 with commit b7096a a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation