DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issue has been patched in version 10.0.1.
History

Sat, 21 Jun 2025 03:00:00 +0000

Type Values Removed Values Added
Description DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issue has been patched in version 10.0.1.
Title DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-21T02:40:38.257Z

Updated: 2025-06-21T02:40:38.257Z

Reserved: 2025-06-17T02:28:39.718Z

Link: CVE-2025-52485

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-06-21T03:15:23.767

Modified: 2025-06-21T03:15:23.767

Link: CVE-2025-52485

cve-icon Redhat

No data.