DNN Stored Cross-Site Scripting Vulnerability via Uploaded SVG Files

Vulnerability

A stored cross-site scripting vulnerability has been identified in DNN (formerly DotNetNuke) versions prior to 9.13.9. This issue arises from the fact that uploaded SVG files could contain scripts. If these files were rendered inline, the embedded scripts could execute, leading to XSS attacks.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files could execute scripts when rendered inline.

Reproduction

The vulnerability can be reproduced by uploading an SVG file containing a script into a DNN instance running a version prior to 9.13.9. Once uploaded, if the SVG file is rendered inline, the script will execute, demonstrating the cross-site scripting vulnerability.

Remediation

Users can upgrade to DNN version 9.13.9 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
6.2
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.