DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- < 9.13.9
A stored cross-site scripting vulnerability has been identified in DNN (formerly DotNetNuke) versions prior to 9.13.9. This issue arises from the fact that uploaded SVG files could contain scripts. If these files were rendered inline, the embedded scripts could execute, leading to XSS attacks.
Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files could execute scripts when rendered inline.
The vulnerability can be reproduced by uploading an SVG file containing a script into a DNN instance running a version prior to 9.13.9. Once uploaded, if the SVG file is rendered inline, the script will execute, demonstrating the cross-site scripting vulnerability.
Users can upgrade to DNN version 9.13.9 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.