CVE-2018-14486: XSS
Published Mar 17, 2019
·Updated
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
Affected Software
2 affected components
nuget/DotNetNuke.Core<=9.1.1
dnnsoftware Dotnetnuke=9.1.1
Event History
Mar 17, 2019
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
May 14, 2022
Advisory Published
01:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-14486?
CVE-2018-14486 is classified as a medium-severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-14486?
To fix CVE-2018-14486, upgrade DNN to version 9.1.2 or later, which includes a patch for the XSS vulnerability.
3
What types of attacks can CVE-2018-14486 be used for?
CVE-2018-14486 can be exploited to perform cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages.
4
Is my DNN installation affected by CVE-2018-14486?
If you are using DNN version 9.1.1 or earlier, your installation is affected by CVE-2018-14486 and you should take action immediately.
5
What are the implications of CVE-2018-14486 for web applications?
The implications of CVE-2018-14486 include potential data theft, session hijacking, and defacement of web applications due to XSS vulnerabilities.