Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim browsers. | |
| Title | Orchard Core RC1 - Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-30T16:32:21.964Z
Reserved: 2026-01-28T18:18:30.522Z
Link: CVE-2020-37019
Updated: 2026-01-30T16:32:19.087Z
Status : Received
Published: 2026-01-30T17:16:11.333
Modified: 2026-01-30T17:16:11.333
Link: CVE-2020-37019
No data.
OpenCVE Enrichment
No data.