DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- < 10.1.0
A stored cross-site scripting vulnerability has been identified in the DNN (DotNetNuke) Prompt module, prior to version 10.1.0. The issue arises because the Prompt module can execute commands that return raw HTML. Malicious input, even if sanitized for other displays, can be executed through certain commands, potentially leading to script execution. This vulnerability is particularly concerning in the context of a super-user.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to DNN version 10.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.