Cross-site scripting in DotNetNuke - #VU146085

 

Cross-site scripting in DotNetNuke - #VU146085

Published: August 28, 2026


Vulnerability identifier: #VU146085
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting (XSS) in the HTML module when storing HTML content with embedded JavaScript. A remote user can submit crafted HTML module content to execute arbitrary JavaScript in the victim\'s browser.

This issue affects environments where content editing permissions are granted to users who are not fully trusted.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins