QID 995351

Date Published: 2023-09-22

QID 995351: DotNet (Nuget) Security Update for DotNetNuke.Core (GHSA-xr96-7ccp-pg5c)

Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN), caused by improper validation of user-supplied input by an unspecified script. Pass through values were not getting filtered, leaving them vulnerable to XSS. A remote attacker could exploit this vulnerability using various parameters in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Github security advisory GHSA-xr96-7ccp-pg5c for updates and patch information.
    Vendor References

    CVEs related to QID 995351

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xr96-7ccp-pg5c DotNetNuke.Core URL Logo github.com/advisories/GHSA-xr96-7ccp-pg5c