VDB
Sign up
MEDIUM

GHSA-m4hf-fxcg-cp34

DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline

Quick fix

GHSA-m4hf-fxcg-cp34 — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 9.13.9

Details

Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 9.13.9
Fixdotnet add package DotNetNuke.Core --version 9.13.9

References