CVE-2015-5520
Summary
| CVE | CVE-2015-5520 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-07-14 16:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Orchardproject | Orchard | 1.7.3 | All | All | All |
| Application | Orchardproject | Orchard | 1.8 | All | All | All |
| Application | Orchardproject | Orchard | 1.8.1 | All | All | All |
| Application | Orchardproject | Orchard | 1.8.2 | All | All | All |
| Application | Orchardproject | Orchard | 1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Project Zero - IT Security Services & Research » CVE-2015-5520 – Orchard Persistent XSS Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | projectzero.gr | Exploit |
| Orchard CMS 1.9.0 / 1.8.2 / 1.7.3 Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| Orchard CMS 1.7.3, 1.8.2, 1.9.0 - Stored XSS Vulnerability - Exploits Database | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Patch 20150630 - Orchard Documentation | af854a3a-2127-422b-91ae-364da2661108 | docs.orchardproject.net | Patch, Vendor Advisory |
| Full Disclosure: Orchard CMS - Persistent XSS vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.