Launch Week Day 1: Announcing Security Design Review
UNKNOWN NuGet

DotNetNuke (DNN) Cross-site scripting (XSS) vulnerability via the __dnnVariable parameter

GHSA-rvrj-j7cc-236p · CVE-2013-4649

Published · Modified

Description

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

Ready to move

Start Securing

Free, no credit card | First findings in minutes