CVE-2019-12562

MEDIUM6.1EPSS 38.7%

Stored Cross-Site Scripting vulnerability in admin component of DotNetNuke

Published: 11/18/2019Modified: 2/16/2024

Description

Cross-site scripting (XSS) is possible in DNN (formerly DotNetNuke) before 9.4.0 by remote authenticated users via the Display Name field in the admin notification function.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (3)