First published: Wed Apr 09 2025(Updated: )
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
DotNetNuke | <9.13.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32373 has a medium severity rating due to its potential to allow unauthorized access to portal files.
The fix for CVE-2025-32373 involves upgrading to DNN version 9.13.9 or later.
CVE-2025-32373 affects DNN versions up to and including 9.13.8.
CVE-2025-32373 impacts registered users in certain configurations of DNN who may gain unauthorized file access.
CVE-2025-32373 is an access control vulnerability allowing users to enumerate or access files improperly.