MEDIUM6.1
GHSA-pf4h-vrv6-cmvr
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Quick fix
GHSA-pf4h-vrv6-cmvr — DNN.PLATFORM: upgrade to the fixed version with the command below.
dotnet add package DNN.PLATFORM --version 10.0.1Details
DNN.PLATFORM allows specially crafted content in URLs could be used with TokenReplace and not be properly sanitized by some SkinObjects. This vulnerability is fixed in 10.0.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DNN.PLATFORM
Introduced in:
6.0.0Fixed in: 10.0.1Fix
dotnet add package DNN.PLATFORM --version 10.0.1