QID 981297
QID 981297: Dotnet (nuget) Security Update for DotNetNuke.Core (GHSA-5c66-x4wm-rjfx)
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-5c66-x4wm-rjfx for updates pertaining to this vulnerability.
Vendor References
- GHSA-5c66-x4wm-rjfx -
github.com/advisories/GHSA-5c66-x4wm-rjfx
CVEs related to QID 981297
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5c66-x4wm-rjfx | DotNetNuke.Core |
|