« Volver al listado

CVE-2022-32173

Estado: ModificadaMedia (5.4)—

In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-32173",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerabilitylab@mend.io",
      "affectedData": [
        {
          "vendor": "OrchardCore",
          "product": "OrchardCore",
          "versions": [
            {
              "status": "affected",
              "version": "v0.0.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "rc2-13929"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-03T13:15:09.737",
  "references": [
    {
      "url": "https://github.com/OrchardCMS/OrchardCore/commit/0163c88ddeaca39815d7e6e5ea1c8391085cc136",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "vulnerabilitylab@mend.io"
    },
    {
      "url": "https://www.mend.io/vulnerability-database/CVE-2022-32173",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "vulnerabilitylab@mend.io"
    },
    {
      "url": "https://github.com/OrchardCMS/OrchardCore/commit/0163c88ddeaca39815d7e6e5ea1c8391085cc136",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mend.io/vulnerability-database/CVE-2022-32173",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerabilitylab@mend.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users."
    },
    {
      "lang": "es",
      "value": "En OrchardCore versiones rc1-11259 a v1.2.2, es vulnerable a una inyección de HTML, lo que permite a un usuario autenticado con un rol de seguridad de editor inyectar un componente de diálogo modal HTML persistente en el tablero de instrumentos que afectará a usuarios administradores"
    }
  ],
  "lastModified": "2026-06-17T04:46:48.760",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:orchardcore:orchardcore:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D600A06B-A974-4B92-BB33-8F4E017DD973",
              "versionEndExcluding": "1.4.0",
              "versionStartIncluding": "0.0.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerabilitylab@mend.io"
}