VDB
Sign up
MEDIUM5.4

GHSA-wwc9-wmm3-2pmf

DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed

Quick fix

GHSA-wwc9-wmm3-2pmf — DNN.PLATFORM: upgrade to the fixed version with the command below.

dotnet add package DNN.PLATFORM --version 10.0.1

Details

DNN.PLATFORM allows a specially crafted request can inject scripts in the Activity Feed Attachments endpoint which will then render in the feed, resulting in a cross-site scripting attack. This vulnerability is fixed in 10.0.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DNN.PLATFORM
Introduced in: 6.0.0Fixed in: 10.0.1
Fixdotnet add package DNN.PLATFORM --version 10.0.1

References