MEDIUM
GHSA-m4hf-fxcg-cp34
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Quick fix
GHSA-m4hf-fxcg-cp34 — DotNetNuke.Core: upgrade to the fixed version with the command below.
dotnet add package DotNetNuke.Core --version 9.13.9Details
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DotNetNuke.Core
Introduced in:
0Fixed in: 9.13.9Fix
dotnet add package DotNetNuke.Core --version 9.13.9