CVE-2025-52487: DNN.PLATFORM possibly allows bypass of IP Filters
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.
Other sources
DNN.PLATFORM allows a specially crafted request or proxy to be created that would bypass the design of DNN Login IP Filters allowing login attempts from IP Adresses not in the allow list. This vulnerability is fixed in 10.0.1.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52487?
The severity of CVE-2025-52487 is considered significant due to its potential to bypass IP filters.
How do I fix CVE-2025-52487?
To fix CVE-2025-52487, upgrade to DNN.PLATFORM version 10.0.1 or later.
What type of vulnerability is CVE-2025-52487?
CVE-2025-52487 is a security flaw that allows unauthorized login attempts by bypassing IP filters.
Who is affected by CVE-2025-52487?
CVE-2025-52487 affects all users of DNN.PLATFORM versions from 7.0.0 up to 10.0.0.
What is DNN.PLATFORM's response to CVE-2025-52487?
DNN.PLATFORM has released a patch in version 10.0.1 to address CVE-2025-52487.