VDB
Sign up
MEDIUM6.9

GHSA-jjwg-4948-6wxp

DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer

Quick fix

GHSA-jjwg-4948-6wxp — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 9.13.10

Details

A content editor could inject scripts in module headers/footers that would run for other users.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 9.0.0Fixed in: 9.13.10
Fixdotnet add package DotNetNuke.Core --version 9.13.10
NuGet/DotNetNuke.Core
Introduced in: 10.0.0Fixed in: 10.2.0
Fixdotnet add package DotNetNuke.Core --version 10.2.0

References