You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
CVE-2019-12562 - Medium Severity Vulnerability
DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to dependency file: /Modules/CloudFlareClearCache/Upendo.Modules.CloudFlareClearCache.csproj
Path to vulnerable library: /s/dotnetnuke.core/9.2.1.533/dotnetnuke.core.9.2.1.533.nupkg
Dependency Hierarchy:
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
Publish Date: 2019-09-26
URL: CVE-2019-12562
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12562
Release Date: 2019-09-26
Fix Resolution: 9.4.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: