PT-2025-39193 · Dotnetnuke · Dnn

Bdukes

·

Published

2025-02-19

·

Updated

2025-09-29

·

CVE-2025-59821

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) versions prior to 10.1.0
Description DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. The application does not sufficiently neutralize or encode characters that are meaningful in HTML, potentially allowing an attacker to cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. This is a reflected cross-site scripting issue.
Recommendations Update to version 10.1.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-02488
CVE-2025-59821
GHSA-JC4G-C8WW-5738

Affected Products

Dnn