CVE-2025-48376: Dnn.Platform's Site Import could use an external source with a crafted request
Published May 23, 2025
·Updated
A malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported.
Affected Software
3 affected componentsFixes available
DNN Dnn.Platform<9.13.9
nuget/DotNetNuke.SiteExportImport<9.13.9
9.13.9
dnnsoftware Dotnetnuke<9.13.9
Remediation
Event History
May 23, 2025
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·04:11 PM
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48376?
CVE-2025-48376 has a high severity as it allows a malicious SuperUser to exploit site exports.
2
How do I fix CVE-2025-48376?
To mitigate CVE-2025-48376, upgrade DNN Dnn.Platform to version 9.13.9 or later.
3
Who is affected by CVE-2025-48376?
CVE-2025-48376 affects all DNN Dnn.Platform versions prior to 9.13.9.
4
Can CVE-2025-48376 allow for remote code execution?
Yes, if exploited, CVE-2025-48376 could potentially lead to unauthorized access or remote code execution.
5
What should I do if I can't immediately upgrade to fix CVE-2025-48376?
If an immediate upgrade is not possible, consider restricting access to SuperUser accounts while implementing additional security measures.