Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 NuGet

Stored Cross-Site Scripting vulnerability in admin component of DotNetNuke

GHSA-5whq-j5qg-wjvp · CVE-2019-12562

Published · Modified

Description

Cross-site scripting (XSS) is possible in DNN (formerly DotNetNuke) before 9.4.0 by remote authenticated users via the Display Name field in the admin notification function.

Ready to move

Start Securing

Free, no credit card | First findings in minutes