DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
References:GSA_kwCzR0hTQS1tNnc5LThjeGMtamZmN84AATzw
DNN XSS Vulnerability
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
nuget:DotNetNuke.Core | <= 9.1.1 | No known fixed version | |
Affected Version RangesAll affected versions6.0.0, 7.0.0, 7.1.0, 7.1.2 |