Showing 3 vulnerabilities on this page for DotNetNuke (DNN)

Signals CISA KEV Ransomware Nuclei
dnnsoftware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.

CWE-434Oct 28, 20251 related artifact
CVSS10.0v3.1EPSS44.7%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.

CWE-200Jun 21, 20251 related artifact
CVSS8.6v3.1EPSS32%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

High severity vulnerability that affects DotNetNuke.Core

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

CWE-918Jul 3, 20181 related artifact
CVSS7.5v3.0EPSS12.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX