GHSA-62mf-vhhw-xmf8

Suggest an improvement
Source
https://github.com/advisories/GHSA-62mf-vhhw-xmf8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-62mf-vhhw-xmf8/GHSA-62mf-vhhw-xmf8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-62mf-vhhw-xmf8
Aliases
Published
2025-05-23T16:11:14Z
Modified
2025-05-23T19:11:28.224659Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L CVSS Calculator
Summary
DNN site Import could use an external source with a crafted request
Details

A malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported.

Database specific
{
    "nvd_published_at": "2025-05-23T16:15:27Z",
    "cwe_ids": [
        "CWE-841"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2025-05-23T16:11:14Z"
}
References

Affected packages

NuGet / DotNetNuke.SiteExportImport

Package

Name
DotNetNuke.SiteExportImport
View open source insights on deps.dev
Purl
pkg:nuget/DotNetNuke.SiteExportImport

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.13.9

Affected versions

9.*

9.1.1.129
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0-ci0000
9.13.0
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5-ci0062
9.13.5
9.13.6
9.13.7
9.13.8