HIGH7.6
GHSA-vm5q-8qww-h238
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
Quick fix
GHSA-vm5q-8qww-h238 — DotNetNuke.Core: upgrade to the fixed version with the command below.
dotnet add package DotNetNuke.Core --version 10.2.0Details
A module friendly name could include scripts that will run during some module operations in the Persona Bar.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DotNetNuke.Core
Introduced in:
9.0.0No fixed version published yet for DotNetNuke.Core (nuget). Pin to a known-safe version or switch to an alternative.
NuGet/DotNetNuke.Core
Introduced in:
10.0.0Fixed in: 10.2.0Fix
dotnet add package DotNetNuke.Core --version 10.2.0