Note: This is fixed in Orchard 1.10, this post is about Orchard 1.8.1.0.
CVE-2929-29592 - Unrestricted File Upload via Media Folder and TinyMCE HTML Editor:
Not allowed because these are the allowed file types:
But we can...
Success!
CVE-2020-29593 - XSS via Media Types Settings
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29592
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29593
No comments:
Post a Comment