Cross-site Scripting (XSS) - Reflected in orchardcms/orchardcore

Valid

Reported on

Feb 11th 2022


Description

Reflected XSS is found under Design>Shortcode>New Shortcode

Proof of Concept

POC Video https://drive.google.com/file/d/1yFfa7g8MMUvJrrKTpJXZEHhQLRSZ1Cii/view?usp=sharing

Impact

Through this vulnerability, an attacker is capable to execute malicious scripts.

We are processing your report and will contact the orchardcms/orchardcore team within 24 hours. 3 months ago
We have contacted a member of the orchardcms/orchardcore team and are waiting to hear back 3 months ago
We have sent a follow up to the orchardcms/orchardcore team. We will try again in 7 days. 3 months ago
We have sent a second follow up to the orchardcms/orchardcore team. We will try again in 10 days. 3 months ago
orchardcms/orchardcore maintainer validated this vulnerability 3 months ago
shubh123-tri has been awarded the disclosure bounty
The fix bounty is now up for grabs
We have sent a fix follow up to the orchardcms/orchardcore team. We will try again in 7 days. 3 months ago
orchardcms/orchardcore maintainer confirmed that a fix has been merged on b7096a 2 months ago
The fix bounty has been dropped
to join this conversation