VDB
Sign up
CRITICAL9.1

GHSA-w9pf-h6m6-v89h

DotNetNuke.Core Vulnerable to Stored XSS via Module Title

Quick fix

GHSA-w9pf-h6m6-v89h — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 9.13.10

Details

Module title supports richtext which could include scripts that would execute in certain scenarios.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 9.13.10
Fixdotnet add package DotNetNuke.Core --version 9.13.10
NuGet/DotNetNuke.Core
Introduced in: 10.0.0Fixed in: 10.2.0
Fixdotnet add package DotNetNuke.Core --version 10.2.0

References