CVE-2025-32036: DNN allows the possibility of bypassing Captcha
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic requests by building a robot and using this tool. This vulnerability is fixed in 9.13.8.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32036?
CVE-2025-32036 is considered a medium severity vulnerability due to its potential to allow automated attacks via easily readable captcha images.
How do I fix CVE-2025-32036?
To fix CVE-2025-32036, update to the latest version of DNN that addresses the captcha image generation fault.
Which versions of DNN are affected by CVE-2025-32036?
CVE-2025-32036 affects DNN versions up to 9.13.8.
What type of vulnerability is CVE-2025-32036?
CVE-2025-32036 is a vulnerability related to inadequate captcha complexity, impacting the effectiveness of bot prevention measures.
Who should be concerned about CVE-2025-32036?
Web administrators and users of DNN versions up to 9.13.8 should be concerned about CVE-2025-32036 due to its implications for security against automated attacks.