PT-2025-39190 · Dotnetnuke · Dnn

Bdukes

·

Published

2025-02-19

·

Updated

2025-09-29

·

CVE-2025-59539

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) versions prior to 10.1.0
Description DNN (formerly DotNetNuke) is an open-source web content management platform. Prior to version 10.1.0, the Biography field allowed injection of javascript code, even when not configured for rich-text input. This code could execute in the context of the website for any user viewing the profile, including administrators and superusers.
Recommendations Update to version 10.1.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02483
CVE-2025-59539
GHSA-7RCC-Q6RQ-JPCM

Affected Products

Dnn