DNN (DotNetNuke) versions prior to 10.2.2 contain a stored cross-site scripting vulnerability that allows authenticated users to upload specially crafted SVG files containing executable scripts. These scripts can be triggered against both authenticated and unauthenticated users, with heightened risk if executed by privileged users. The vulnerability affects this popular open-source content management platform widely used in Microsoft ecosystems. The vulnerability carries a CVSS score of 8.0 (HIGH) with a network-based attack vector requiring low authentication privileges and user interaction. The attack complexity is moderate, and successful exploitation could result in high-impact consequences including confidentiality, integrity, and availability compromise. The FAUCET Risk Score of 49.0 indicates moderate overall risk when considering additional contextual factors. There is currently no evidence of active exploitation in the wild. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List, suggesting minimal community attention or available public exploit code. Organizations should prioritize patching to version 10.2.2 as part of standard maintenance activities, though immediate emergency response is not warranted based on current exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.2.2CPE matchmatch criteria | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.