Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 NuGet

Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN)

GHSA-5c66-x4wm-rjfx · CVE-2016-7119

Published · Modified

Description

Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.

Ready to move

Start Securing

Free, no credit card | First findings in minutes