CVE-2020-37103
Last modified
CVE-2020-37103 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dnnsoftware | Dotnetnuke | <= 9.5.0 |
References
- http://dnnsoftware.com/Product
- https://www.exploit-db.com/exploits/48124Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/dotnetnuke-persistent-cross-site-scriptingThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-37103?
How severe is CVE-2020-37103?
How do I fix CVE-2020-37103?
Are you affected by CVE-2020-37103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
