MEDIUM6.9
GHSA-jjwg-4948-6wxp
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
Quick fix
GHSA-jjwg-4948-6wxp — DotNetNuke.Core: upgrade to the fixed version with the command below.
dotnet add package DotNetNuke.Core --version 9.13.10Details
A content editor could inject scripts in module headers/footers that would run for other users.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DotNetNuke.Core
Introduced in:
9.0.0Fixed in: 9.13.10Fix
dotnet add package DotNetNuke.Core --version 9.13.10NuGet/DotNetNuke.Core
Introduced in:
10.0.0Fixed in: 10.2.0Fix
dotnet add package DotNetNuke.Core --version 10.2.0