PT-2025-39200 · Dotnetnuke · Dnn

Bdukes

·

Published

2025-02-18

·

Updated

2025-09-29

·

CVE-2025-59548

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) versions prior to 10.1.0
Description DNN (formerly DotNetNuke) is an open-source web content management platform. Versions prior to 10.1.0 have a javascript injection issue related to specially crafted URLs to the FileBrowser. Clicking these URLs can affect users. The issue impacts any unsuspecting user.
Recommendations Update to version 10.1.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-02482
CVE-2025-59548
GHSA-5FJ9-542V-W4RQ

Affected Products

Dnn