CVE-2020-37103: DotNetNuke 9.5 - Persistent Cross-Site Scripting
DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37103?
CVE-2020-37103 is classified as a high severity vulnerability due to its persistent cross-site scripting nature.
How do I fix CVE-2020-37103?
To fix CVE-2020-37103, ensure that all user-uploaded XML files are properly sanitized and validated to prevent malicious script execution.
Who is affected by CVE-2020-37103?
CVE-2020-37103 affects users of DotNetNuke version 9.5 and allows attackers to upload harmful scripts through journal tools.
What types of attacks can CVE-2020-37103 enable?
CVE-2020-37103 can enable persistent cross-site scripting attacks that may lead to data theft or unauthorized actions on behalf of users.
Is there a patch available for CVE-2020-37103?
Yes, the vendor has provided updates and patches that address the vulnerabilities associated with CVE-2020-37103.