CVE-2025-52487
DNN.PLATFORM possibly allows bypass of IP Filters
EPSS 0.29%
Description
DNN.PLATFORM allows a specially crafted request or proxy to be created that would bypass the design of DNN Login IP Filters allowing login attempts from IP Adresses not in the allow list. This vulnerability is fixed in 10.0.1.
How to fix CVE-2025-52487
To remediate CVE-2025-52487, upgrade the affected package to a fixed version below.
- NuGet/DNN.PLATFORM—upgrade to 10.0.1 or later
Is CVE-2025-52487 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 7.0.0, < 10.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N |