Improper access control in DotNetNuke - CVE-2025-48376
Published: May 23, 2025 / Updated: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to modify data and cause a denial of service.
The vulnerability exists due to improper access control in the site import feature when handling a crafted request that uses an external source. A remote privileged user can send a specially crafted request to modify data and cause a denial of service.
User interaction is required.