VYPR
High severityNVD Advisory· Published Jun 21, 2025· Updated Jun 23, 2025

DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

CVE-2025-52488

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
DNN.PLATFORMNuGet
>= 6.0.0, < 10.0.110.0.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.