CVE-2022-47053: XSS
Published Apr 12, 2023
·Updated
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
Affected Software
1 affected component
dnnsoftware Dotnetnuke>=7.0.0<=9.10.2
Event History
Apr 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-47053?
CVE-2022-47053 is an arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2.
2
How does CVE-2022-47053 work?
CVE-2022-47053 allows attackers to execute arbitrary code by uploading a crafted SVG file.
3
How severe is CVE-2022-47053?
CVE-2022-47053 has a severity rating of 5.4, which is considered medium.
4
How can I fix CVE-2022-47053?
To fix CVE-2022-47053, update your DNN Corp DotNetNuke installation to a version higher than v9.10.2.
5
Where can I find more information about CVE-2022-47053?
You can find more information about CVE-2022-47053 on the DNN Software security center: https://www.dnnsoftware.com/community/security/security-center