Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-30 17:16
Updated : 2026-01-30 17:16
NVD link : CVE-2020-37019
Mitre link : CVE-2020-37019
CVE.ORG link : CVE-2020-37019
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
