DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dnnsoftware
Dnnsoftware dnn Platform |
|
| Vendors & Products |
Dnnsoftware
Dnnsoftware dnn Platform |
Tue, 28 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1. | |
| Title | DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-28T21:46:11.267Z
Updated: 2025-10-29T14:51:08.317Z
Reserved: 2025-10-27T15:26:14.126Z
Link: CVE-2025-64095
Updated: 2025-10-29T14:51:02.005Z
Status : Received
Published: 2025-10-28T22:15:38.387
Modified: 2025-10-28T22:15:38.387
Link: CVE-2025-64095
No data.
ReportizFlow