icon

We found results for “

CVE-2025-48376

Good to know:

icon

Date: May 23, 2025

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Enforcement of Behavioral Workflow

CWE-841

Top Fix

icon

Upgrade Version

Upgrade to version DotNetNuke.SiteExportImport - 9.13.9;dotnetnuke.siteexportimport - 9.13.9;https://github.com/dnnsoftware/Dnn.Platform.git - v9.13.9

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us