Vulnerability Details CVE-2022-37720
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.3%
CVSS Severity
CVSS v3 Score 9.0
Products affected by CVE-2022-37720
-
cpe:2.3:a:orchardcore:orchard_cms:1.10.3