We found results for “”
CVE-2025-48376
Good to know:
Date: May 23, 2025
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Enforcement of Behavioral Workflow
CWE-841Top Fix
Upgrade Version
Upgrade to version DotNetNuke.SiteExportImport - 9.13.9;dotnetnuke.siteexportimport - 9.13.9;https://github.com/dnnsoftware/Dnn.Platform.git - v9.13.9
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | LOW |
| Availability (A): | LOW |
Vulnerabilities
Projects
Contact Us


