CVE-2013-4649

EPSS 0.27%

DotNetNuke (DNN) Cross-site scripting (XSS) vulnerability via the __dnnVariable parameter

發布日:2022/5/17修改日:2024/12/5

描述

Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

受影響套件(1)

參考連結(6)