VDB
Sign up
MEDIUM6.5

GHSA-jc4g-c8ww-5738

DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile

Quick fix

GHSA-jc4g-c8ww-5738 — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 10.1.0

Details

# Summary A reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile

# Description DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 10.1.0
Fixdotnet add package DotNetNuke.Core --version 10.1.0

References