VYPR

DNN CMS

by Dnnsoftware

CVEs (2)

  • CVE-2021-40186MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of…

  • CVE-2021-31858MedJul 20, 2022
    risk 0.35cvss 5.4epss 0.01

    DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.