PT-2026-5852 · Dnnsoftware+1 · Dotnetnuke+1
Sajjad Pourali
·
Published
2026-02-03
·
Updated
2026-02-03
·
CVE-2020-37103
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DotNetNuke version 9.5
Description
A persistent cross-site scripting issue allows normal users to upload malicious XML files containing executable scripts via journal tools. By uploading XML files with XHTML namespace scripts, attackers can execute arbitrary JavaScript in the browsers of other users, which may lead to the bypass of Cross-Site Request Forgery (CSRF) protections—a mechanism used to prevent unauthorized commands from being transmitted from a user the web application trusts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dotnetnuke
Dnn.Platform