MEDIUM5.4
GHSA-wwc9-wmm3-2pmf
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Quick fix
GHSA-wwc9-wmm3-2pmf — DNN.PLATFORM: upgrade to the fixed version with the command below.
dotnet add package DNN.PLATFORM --version 10.0.1Details
DNN.PLATFORM allows a specially crafted request can inject scripts in the Activity Feed Attachments endpoint which will then render in the feed, resulting in a cross-site scripting attack. This vulnerability is fixed in 10.0.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DNN.PLATFORM
Introduced in:
6.0.0Fixed in: 10.0.1Fix
dotnet add package DNN.PLATFORM --version 10.0.1