PT-2025-39193 · Dotnetnuke · Dnn
Bdukes
·
Published
2025-02-19
·
Updated
2025-09-29
·
CVE-2025-59821
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DNN (formerly DotNetNuke) versions prior to 10.1.0
Description
DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. The application does not sufficiently neutralize or encode characters that are meaningful in HTML, potentially allowing an attacker to cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. This is a reflected cross-site scripting issue.
Recommendations
Update to version 10.1.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dnn