CVE-2013-4649

EPSS 0.27%

DotNetNuke (DNN) Cross-site scripting (XSS) vulnerability via the __dnnVariable parameter

Published: 5/17/2022Modified: 12/5/2024

Description

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

Affected packages (1)

References (6)