{"id":"CVE-2022-32173","summary":"OrchardCore - HTML Injection","details":"In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security role to inject a persistent HTML modal dialog component into the dashboard that will affect admin users.","aliases":["GHSA-5gg9-gwj4-mqmj"],"modified":"2026-08-12T03:51:27.220357005Z","published":"2022-10-03T12:25:08.390Z","database_specific":{"cna_assigner":"Mend","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32173.json"},"references":[{"type":"WEB","url":"https://www.mend.io/vulnerability-database/CVE-2022-32173"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32173.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32173"},{"type":"FIX","url":"https://github.com/OrchardCMS/OrchardCore/commit/0163c88ddeaca39815d7e6e5ea1c8391085cc136"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/orchardcms/orchardcore","events":[{"introduced":"a5e171044cf9ad2418493922ed28f580227eba26"},{"fixed":"49cc18fcdeb409ec4ad71569a0e2d41a0d5cad17"},{"fixed":"0163c88ddeaca39815d7e6e5ea1c8391085cc136"}],"database_specific":{"extracted_events":[{"introduced":"0.0.1"},{"fixed":"1.4.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:orchardcore:orchardcore:*:*:*:*:*:*:*:*"}}],"versions":["v0.0.1","v1.3.0","v1.2.0","v1.0.0","v0.0.3","v0.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32173.json"}}],"schema_version":"1.9.0"}