CVE-2025-32373: DNN allows a registered user to enumerate and access files they should not have access to
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32373?
CVE-2025-32373 has a medium severity rating due to its potential to allow unauthorized access to portal files.
How do I fix CVE-2025-32373?
The fix for CVE-2025-32373 involves upgrading to DNN version 9.13.9 or later.
What are the affected versions for CVE-2025-32373?
CVE-2025-32373 affects DNN versions up to and including 9.13.8.
Who is impacted by CVE-2025-32373?
CVE-2025-32373 impacts registered users in certain configurations of DNN who may gain unauthorized file access.
What type of vulnerability is CVE-2025-32373?
CVE-2025-32373 is an access control vulnerability allowing users to enumerate or access files improperly.