-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from incomplete HTML sanitization in the ConfigureHtmlSanitizer configuration. The patch explicitly removes the 'form' tag from AllowedTags (sanitizer.AllowedTags.Remove("form")), indicating this was the attack vector. The AddHtmlSanitizer method in OrchardCoreBuilderExtensions.cs is responsible for configuring the sanitizer's allow-list, making it the root of the vulnerability. The presence of 'form' in allowed tags prior to v1.4.0 allowed attackers to inject modal dialogs with form elements, as demonstrated in the PoC.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| OrchardCore | nuget | >= 1.0.0-rc1-11259, < 1.4.0 | 1.4.0 |
Ongoing coverage of React2Shell