DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- < 9.13.4
A vulnerability in DNN (DotNetNuke) ImageHandler allows for text injection via a crafted URL query string. This text is rendered in an image, potentially misleading users who trust the domain. The issue is present in DNN versions prior to 9.13.4.
Exploitation of this vulnerability could lead to the injection of misleading text into images, causing users to mistakenly trust the information as legitimate.
Users can update to DNN version 9.13.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.