CRITICAL🇵🇱 Wersja polska

CVE-2025-59545

CVSS 9.0v3.1pub. 2025-09-23upd. 2025-09-29

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0.

🤖 AI Analysis
How it works

The Prompt module in DNN allows execution of commands that can return raw HTML code. Malicious input, even if properly sanitized in other places in the application, can be processed by specific Prompt module commands without adequate sanitization. This results in embedding and execution of uncontrolled script code (XSS) in the user's browser.

Impact

An attacker can execute arbitrary JavaScript code in the context of a logged-in user's session, which may lead to account takeover, session data theft, or further compromise of application integrity and confidentiality.

Mitigation & patch

Update the DNN platform to version 10.1.0 or later, where the issue has been fixed. Details available in vendor references: https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2qxc-mf4x-wr29

Who is affected

DNN (DotNetNuke) in all versions before 10.1.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Dnnsoftware Dotnetnuke

    APP
    Dnnsoftware
    < 10.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-24838CRITICAL9.1PL ✓same product

DNN/DotNetNuke: XSS w tytule modułu umożliwia wykonanie skryptów

CVE-2025-64095CRITICAL10.0PL ✓same product

DNN/DotNetNuke: nieuwierzytelnione przesyłanie i nadpisywanie plików (RCE/XSS)

CVE-2015-2794CRITICAL9.8PL ✓same product

DotNetNuke: nieautoryzowana reinstalacja aplikacji i przejęcie konta SuperUser

CVE-2018-15811HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVE-2018-18325HIGH7.5⚠ KEVsame product

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: thi...