Логотип exploitDog
bind:CVE-2025-64094
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64094

Количество 2

Количество 2

nvd логотип

CVE-2025-64094

3 месяца назад

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is fixed in 10.1.1.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-hmvq-8p83-cq52

3 месяца назад

DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64094

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is fixed in 10.1.1.

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-hmvq-8p83-cq52

DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload

CVSS3: 6.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу