CVE-2022-0274:
Cross-site Scripting OrchardCore.Application.Cms.Targets
6.8
CVSS Score
3.0
Basic Information
CVE ID
GHSA ID
EPSS Score
0.36409%
CWE
Published
1/21/2022
Updated
2/3/2023
KEV Status
No
Technology
C#
Technical Details
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
OrchardCore.Application.Cms.Targets | nuget | < 1.2.2 | 1.2.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability patterns show missing input sanitization and improper HTML encoding across multiple components handling user-controllable data:
- Link field/menu item drivers lacked URL validation checks and HTML sanitization of constructed anchor tags
- Error message handling directly interpolated untrusted data into localized strings without encoding
- Workflow helpers used raw strings in localization contexts that bypass HTML encoding
- The patches consistently add HTML sanitization checks, URL validation, and proper encoded string handling via HtmlEncoder and IHtmlSanitizerService injections
- CWE-79 alignment confirms these are classic XSS vectors in web content generation paths