{"api_version":"1","generated_at":"2026-07-23T09:16:49+00:00","cve":"CVE-2015-5520","urls":{"html":"https://cve.report/CVE-2015-5520","api":"https://cve.report/api/cve/CVE-2015-5520.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-5520","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-5520"},"summary":{"title":"CVE-2015-5520","description":"Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-07-14 16:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/","name":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Project Zero - IT Security Services & Research » CVE-2015-5520 – Orchard Persistent XSS Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Orchard CMS 1.9.0 / 1.8.2 / 1.7.3 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/37533/","name":"https://www.exploit-db.com/exploits/37533/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Orchard CMS 1.7.3, 1.8.2, 1.9.0 - Stored XSS Vulnerability - Exploits Database","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.orchardproject.net/Documentation/Patch-20150630","name":"http://docs.orchardproject.net/Documentation/Patch-20150630","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Patch 20150630 - Orchard Documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2015/Jul/32","name":"http://seclists.org/fulldisclosure/2015/Jul/32","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Full Disclosure: Orchard CMS - Persistent XSS vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-5520","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5520","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"5520","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchardproject","cpe5":"orchard","cpe6":"1.7.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5520","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchardproject","cpe5":"orchard","cpe6":"1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5520","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchardproject","cpe5":"orchard","cpe6":"1.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5520","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchardproject","cpe5":"orchard","cpe6":"1.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5520","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchardproject","cpe5":"orchard","cpe6":"1.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:50:02.967Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html"},{"name":"20150706 Orchard CMS - Persistent XSS vulnerability","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2015/Jul/32"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.orchardproject.net/Documentation/Patch-20150630"},{"name":"37533","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/37533/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-07-14T16:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html"},{"name":"20150706 Orchard CMS - Persistent XSS vulnerability","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2015/Jul/32"},{"tags":["x_refsource_MISC"],"url":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.orchardproject.net/Documentation/Patch-20150630"},{"name":"37533","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/37533/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-5520","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/132583/Orchard-CMS-1.9.0-1.8.2-1.7.3-Cross-Site-Scripting.html"},{"name":"20150706 Orchard CMS - Persistent XSS vulnerability","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2015/Jul/32"},{"name":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/","refsource":"MISC","url":"https://projectzero.gr/en/2015/07/orchard-persistent-xss-vulnerability/"},{"name":"http://docs.orchardproject.net/Documentation/Patch-20150630","refsource":"CONFIRM","url":"http://docs.orchardproject.net/Documentation/Patch-20150630"},{"name":"37533","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/37533/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-5520","datePublished":"2015-07-14T16:00:00.000Z","dateReserved":"2015-07-14T00:00:00.000Z","dateUpdated":"2024-09-16T18:08:13.975Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-07-14 16:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:orchardproject:orchard:1.7.3:*:*:*:*:*:*:*","matchCriteriaId":"6B7F5355-5526-4604-90CB-F1857928AB1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:orchardproject:orchard:1.8:*:*:*:*:*:*:*","matchCriteriaId":"667C3DDB-2D95-4F02-9895-1C796D85C5EB"},{"vulnerable":true,"criteria":"cpe:2.3:a:orchardproject:orchard:1.8.1:*:*:*:*:*:*:*","matchCriteriaId":"0E71A861-EA18-40C8-B7B1-8A6115BD57D0"},{"vulnerable":true,"criteria":"cpe:2.3:a:orchardproject:orchard:1.8.2:*:*:*:*:*:*:*","matchCriteriaId":"7144C561-3CC3-47B2-BCC1-5D0967454942"},{"vulnerable":true,"criteria":"cpe:2.3:a:orchardproject:orchard:1.9:*:*:*:*:*:*:*","matchCriteriaId":"B2742E7C-826E-4203-9E5F-F366F1A64508"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"5520","Ordinal":"1","Title":"CVE-2015-5520","CVE":"CVE-2015-5520","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"5520","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.","Type":"Description","Title":"CVE-2015-5520"},{"CveYear":"2015","CveId":"5520","Ordinal":"2","NoteData":"2015-07-14","Type":"Other","Title":"Published"}]}}}