CVE-2025-48377: Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Published May 23, 2025
·Updated
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions.
Affected Software
4 affected componentsFixes available
DNN Dnn.Platform<9.13.9
nuget/DotNetNuke.Core<9.13.9
9.13.9
nuget/DotNetNuke.Web<9.13.9
9.13.9
dnnsoftware Dotnetnuke<9.13.9
Remediation
Event History
May 23, 2025
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyAffected Software
Advisory Published
via GitHub·04:36 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48377?
CVE-2025-48377 is classified as a critical vulnerability due to its potential for XSS attacks that could compromise user data.
2
How do I fix CVE-2025-48377?
To mitigate CVE-2025-48377, upgrade DNN to version 9.13.9 or later.
3
What type of vulnerability is CVE-2025-48377?
CVE-2025-48377 is an XSS (Cross-Site Scripting) vulnerability that can be triggered via specially crafted URLs.
4
Which versions of DNN are affected by CVE-2025-48377?
CVE-2025-48377 affects all versions of DNN prior to version 9.13.9.
5
What are the potential consequences of CVE-2025-48377?
Exploitation of CVE-2025-48377 can lead to unauthorized access to user accounts and injection of malicious scripts.