VDB
Sign up
MEDIUM6.1

GHSA-pf4h-vrv6-cmvr

DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects

Quick fix

GHSA-pf4h-vrv6-cmvr — DNN.PLATFORM: upgrade to the fixed version with the command below.

dotnet add package DNN.PLATFORM --version 10.0.1

Details

DNN.PLATFORM allows specially crafted content in URLs could be used with TokenReplace and not be properly sanitized by some SkinObjects. This vulnerability is fixed in 10.0.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DNN.PLATFORM
Introduced in: 6.0.0Fixed in: 10.0.1
Fixdotnet add package DNN.PLATFORM --version 10.0.1

References