VDB
Sign up
MEDIUM6.1

GHSA-5whq-j5qg-wjvp

Stored Cross-Site Scripting vulnerability in admin component of DotNetNuke

Quick fix

GHSA-5whq-j5qg-wjvp — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 9.4.0

Details

Cross-site scripting (XSS) is possible in DNN (formerly DotNetNuke) before 9.4.0 by remote authenticated users via the Display Name field in the admin notification function.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 9.4.0
Fixdotnet add package DotNetNuke.Core --version 9.4.0

References