CVE-2021-31858: XSS
Published Jul 20, 2022
·Updated
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
Affected Software
1 affected component
dnnsoftware Dotnetnuke<=9.10.2
Event History
Jul 20, 2022
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-31858?
CVE-2021-31858 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-31858?
To fix CVE-2021-31858, update DotNetNuke to version 9.10.3 or later.
3
Who is affected by CVE-2021-31858?
CVE-2021-31858 affects users of DotNetNuke versions up to and including 9.10.2.
4
What type of vulnerability is CVE-2021-31858?
CVE-2021-31858 is a Stored Cross-Site Scripting vulnerability.
5
What can attackers do with CVE-2021-31858?
Attackers can exploit CVE-2021-31858 to inject arbitrary code via a crafted payload into user profiles.