LOW🇵🇱 Wersja polska

CVE-2025-32035

CVSS 2.6v3.1pub. 2025-04-08upd. 2025-08-26

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
  • Dnnsoftware Dotnetnuke

    APP
    Dnnsoftware
    < 9.13.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-24838CRITICAL9.1PL ✓same product

DNN/DotNetNuke: XSS w tytule modułu umożliwia wykonanie skryptów

CVE-2025-64095CRITICAL10.0PL ✓same product

DNN/DotNetNuke: nieuwierzytelnione przesyłanie i nadpisywanie plików (RCE/XSS)

CVE-2025-59545CRITICAL9.0PL ✓same product

XSS w module Prompt platformy DNN (DotNetNuke) — wykonanie skryptu

CVE-2015-2794CRITICAL9.8PL ✓same product

DotNetNuke: nieautoryzowana reinstalacja aplikacji i przejęcie konta SuperUser

CVE-2018-15811HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.