Medium severity6.1NVD Advisory· Published Sep 26, 2019· Updated Jun 17, 2026
CVE-2019-12562
CVE-2019-12562
Description
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
DotNetNuke.CoreNuGet | < 9.4.0 | 9.4.0 |
Affected products
3- DotNetNuke/DotNetNuke (DNN)description
Patches
Vulnerability mechanics
References
5- mayaseven.com/cve-2019-12562-stored-cross-site-scripting-in-dotnetnuke-dnn-version-v9-3-2/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-5whq-j5qg-wjvpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-12562ghsaADVISORY
- packetstormsecurity.com/files/154673/DotNetNuke-Cross-Site-Scripting.htmlnvdWEB
- mayaseven.com/cve-2019-12562-stored-cross-site-scripting-in-dotnetnuke-dnn-version-v9-3-2ghsaWEB
News mentions
0No linked articles in our index yet.