DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- < 10.1.0
A stored cross-site scripting vulnerability has been identified in DNN (formerly DotNetNuke) versions prior to 10.1.0. This issue allows administrators and content editors to inject HTML, including JavaScript, into module titles. Such scripts could be executed, leading to cross-site scripting attacks. While the ability to add HTML in module titles could be a valid use case, the introduction of more roles with this capability raises security concerns.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the module.
Users can update to DNN version 10.1.0 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.