Cross-site Scripting (XSS) - Reflected in orchardcms/orchardcore
Valid
Reported on
Feb 11th 2022
Description
Reflected XSS is found under Design>Shortcode>New Shortcode
Proof of Concept
POC Video https://drive.google.com/file/d/1yFfa7g8MMUvJrrKTpJXZEHhQLRSZ1Cii/view?usp=sharing
Impact
Through this vulnerability, an attacker is capable to execute malicious scripts.
We are processing your report and will contact the
orchardcms/orchardcore
team within 24 hours.
a year ago
We have contacted a member of the
orchardcms/orchardcore
team and are waiting to hear back
a year ago
We have sent a
follow up to the
orchardcms/orchardcore
team.
We will try again in 7 days.
a year ago
We have sent a
second
follow up to the
orchardcms/orchardcore
team.
We will try again in 10 days.
a year ago
We have sent a
fix follow up to the
orchardcms/orchardcore
team.
We will try again in 7 days.
a year ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation