DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 23 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 May 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. | |
Title | Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-23T15:39:03.727Z
Updated: 2025-05-23T16:01:18.090Z
Reserved: 2025-05-19T15:46:00.396Z
Link: CVE-2025-48378

Updated: 2025-05-23T16:01:08.564Z

Status : Awaiting Analysis
Published: 2025-05-23T16:15:27.580
Modified: 2025-05-28T14:58:52.920
Link: CVE-2025-48378

No data.