VDB
Sign up
MEDIUM6.3

GHSA-7rcc-q6rq-jpcm

DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field

Quick fix

GHSA-7rcc-q6rq-jpcm — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 10.1.0

Details

## Summary Users can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios

## Description When embedding information in the `Biography` field, even if that field is not rich-text, users could inject javascript code that would run in the context of the website and to any other user that can view the profile including administrators and/or superusers.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 10.1.0
Fixdotnet add package DotNetNuke.Core --version 10.1.0

References