Record summary

CVE-2020-37103 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 9.5affected

Proofs of concept

1

Catalogued exploits

ExploitDBDotNetNuke 9.5 - Persistent Cross-Site ScriptingExploitDB exploitby Sajjad PouraliNot analyzed1 file
ExploitDB

PoC details

References

5