CNNVD-202509-3656 Information
CNNVD ID
CNNVD-202509-3656
Related CVE
- CNNVD Published: 2025-09-23
Description (Chinese)
DNN(又名DotNetNuke)是美国DNN公司的一套由微软支持、基于ASP.NET平台的开源内容管理系统(CMS)。该系统具有易于安装、可扩展、功能丰富等特点。 DNN 10.1.0之前版本存在跨站脚本漏洞,该漏洞源于特制URL容易受到javascript注入攻击,可能影响点击链接的用户。
Description (English)
DNN (also known as DotNetNuke) is an open-source content management system (CMS) supported by Microsoft and based on the ASP.NET platform by United States DNN. The system has features that are easy to install, scalable and functional. The pre-DNN 10.1.0 version had a cross-site script loophole, which stemmed from the fact that the unique URL was vulnerable to javascript injections and could affect the users of the link.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
dnsmasq
Published
2025-09-23
Last Modified
2026-02-24
References
https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-5fj9-542v-w4rq
Patch
https://github.com/dnnsoftware/Dnn.Platform/releases/tag/v10.1.0
Share on: