Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jc4g-c8ww-5738: DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile

Summary

A reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile

Description

DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML.

ghsa
#xss#vulnerability#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-59821

DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile

Moderate severity GitHub Reviewed Published Sep 23, 2025 in dnnsoftware/Dnn.Platform • Updated Sep 23, 2025

Package

nuget DotNetNuke.Core (NuGet)

Affected versions

< 10.1.0

Summary

A reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile

Description

DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML.

References

  • GHSA-jc4g-c8ww-5738
  • https://nvd.nist.gov/vuln/detail/CVE-2025-59821

Published to the GitHub Advisory Database

Sep 23, 2025

Last updated

Sep 23, 2025

ghsa: Latest News

GHSA-jjjj-jwhf-8rgr: MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS