Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-32035

Опубликовано: 08 апр. 2025
Источник: nvd
CVSS3: 2.6
CVSS3: 7.5
EPSS Низкий

Описание

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*
Версия до 9.13.2 (исключая)

EPSS

Процентиль: 22%
0.00071
Низкий

2.6 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-351

EPSS

Процентиль: 22%
0.00071
Низкий

2.6 Low

CVSS3

7.5 High

CVSS3

Дефекты

CWE-351