DNN Stored Cross-Site Scripting Vulnerability via SVG Upload

Vulnerability

A stored cross-site scripting vulnerability has been identified in DNN (formerly DotNetNuke) versions prior to 10.1.1. This issue arises from inadequate sanitization of uploaded SVG files, which failed to address all potential cross-site scripting scenarios. The vulnerability is a result of an incomplete fix for CVE-2025-48378, allowing malicious SVG files to be uploaded and execute arbitrary JavaScript in the context of the user's browser. This could lead to various attacks, including data exfiltration, session hijacking, and defacement of the web application.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript code in the user's browser, potentially leading to data exfiltration, session hijacking, and defacement of the web application.

Remediation

Users can upgrade to DNN version 10.1.1 or later to address this vulnerability.

Added: Oct 28, 2025, 10:18 PM
Updated: Oct 28, 2025, 10:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.1
exploitability
5.4
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.