EDB-ID: 48456 CVE: N/A Author: SUNCSR Type: WEBAPPS Edb Verified: ✗ Exploit: [Download]() / [Test]() Platform: ASPX Vulnerable App: Date: 2020-05-12 Exploit Title: Orchard Core RC1 - Persistent Cross-Site Scripting Google Dork: "Orchardcms" Date: 2020-05-07 Exploit Author: SunCSR (Sun Cyber Security Research) Vendor Homepage: http://www.orchardcore.net/ Software Link: https://github.com/OrchardCMS/OrchardCore Version: RC1 Tested on: Windows CVE: N/A Vulnerability: Persistent Cross-Site Scripting + Persistent Cross-site scripting (Stored XSS) vulnerabilities in Orchard CMS - Orchard Core RC1 allow remote attackers to inject arbitrary web script or HTML Test XSS: + Various form data entries were crafted to exploit the Stored XSS vulnerability + A script to alert a cookie value was included as a payload to demonstrate the exploit Reference: https://github.com/OrchardCMS/OrchardCore/issues/5802 History**: + 2020-03-23 Issue discovered + 2020-03-27 Vendor contacted + 2020-04-22 Vendor response and hotfix + 2020-04-22 Vendor set patch milestone to rc2