DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dnnsoftware
Dnnsoftware dotnetnuke |
|
CPEs | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dnnsoftware
Dnnsoftware dotnetnuke |
Tue, 08 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2. | |
Title | DNN does not check the contents of a file when uploading files | |
Weaknesses | CWE-351 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-08T18:27:55.670Z
Reserved: 2025-04-01T21:57:32.959Z
Link: CVE-2025-32035

Updated: 2025-04-08T18:27:50.916Z

Status : Analyzed
Published: 2025-04-08T18:16:08.597
Modified: 2025-08-26T00:54:51.967
Link: CVE-2025-32035

No data.