{"id":"GHSA-r8hp-5m7c-jhv4","summary":"Cross-site Scripting OrchardCore.Application.Cms.Targets","details":"Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.","aliases":["CVE-2022-0274"],"modified":"2023-11-08T04:07:31.500592Z","published":"2022-01-21T23:08:50Z","database_specific":{"github_reviewed_at":"2022-01-21T21:09:59Z","nvd_published_at":"2022-01-19T18:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0274"},{"type":"WEB","url":"https://github.com/orchardcms/orchardcore/commit/218f25ddfadb66a54de7a82dffe3ab2e4ab7c4b4"},{"type":"PACKAGE","url":"https://github.com/orchardcms/orchardcore"},{"type":"WEB","url":"https://huntr.dev/bounties/a82a714a-9b71-475e-bfc3-43326fcaf764"}],"affected":[{"package":{"name":"OrchardCore.Application.Cms.Targets","ecosystem":"NuGet","purl":"pkg:nuget/OrchardCore.Application.Cms.Targets"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"versions":["1.0.0","1.0.0-beta1-3383","1.0.0-beta1-3667","1.0.0-beta2-67531","1.0.0-beta2-67581","1.0.0-beta2-67846","1.0.0-beta2-69590","1.0.0-beta2-70992","1.0.0-beta3-71075","1.0.0-beta3-71077","1.0.0-rc1-10004","1.0.0-rc2-13450","1.1.0","1.2.0","1.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-r8hp-5m7c-jhv4/GHSA-r8hp-5m7c-jhv4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H"}]}