DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
The module title field in DNN accepts content in rich text format, which allows embedding malicious JavaScript code. In certain page rendering scenarios, the embedded script is executed by the user's browser without proper input sanitization. The vulnerability requires administrative privileges (PR:H) to inject the payload, however its impact extends beyond the attacker's context (Scope:Changed).
An attacker with administrator privileges can inject malicious scripts that will be executed in the context of other users' browsers, which may lead to session theft, account takeover, or sensitive data disclosure.
DNN should be updated to version 9.13.10 or 10.2.0, which contain patches eliminating the vulnerability. Details are available in the vendor's references on GitHub Security Advisory.
DNN (DotNetNuke) in all versions before 9.13.10 and before 10.2.0
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HDnnsoftware Dotnetnuke
APPDnnsoftware< 9.13.1010.0.0 – 10.2.0 (excl.)
Related vulnerabilities
DNN/DotNetNuke: nieuwierzytelnione przesyłanie i nadpisywanie plików (RCE/XSS)
XSS w module Prompt platformy DNN (DotNetNuke) — wykonanie skryptu
DotNetNuke: nieautoryzowana reinstalacja aplikacji i przejęcie konta SuperUser
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: thi...