VDB
Sign up
MEDIUM

GHSA-rvrj-j7cc-236p

DotNetNuke (DNN) Cross-site scripting (XSS) vulnerability via the __dnnVariable parameter

Quick fix

GHSA-rvrj-j7cc-236p — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 6.2.9

Details

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 6.2.9
Fixdotnet add package DotNetNuke.Core --version 6.2.9
NuGet/DotNetNuke.Core
Introduced in: 7.0Fixed in: 7.1.1
Fixdotnet add package DotNetNuke.Core --version 7.1.1

References