Home

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.

PUBLISHED Reserved 2025-05-19 | Published 2025-05-23 | Updated 2025-05-23 | Assigner GitHub_M




LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L

Problem types

CWE-841: Improper Enforcement of Behavioral Workflow

Product status

< 9.13.9
affected

References

github.com/...atform/security/advisories/GHSA-62mf-vhhw-xmf8

github.com/...ommit/13fb13ee76173c3467d7ee8d120b20ca7bd4fa63

cve.org (CVE-2025-48376)

nvd.nist.gov (CVE-2025-48376)

Download JSON