CVE 4.3 MEDIUM

DNN CKEditor Provider allows unauthenticated upload out-of-the-box_CVE-2025-62802

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations. This vulnerability is fixed in 10.1.1.

Basic Information

ID CVE-2025-62802
Source GitHub_M
Published Oct 28, 2025 at 21:42

Affected Product

Vendor dnnsoftware
Product Dnn.Platform
Version < 10.1.1
Affected Versions dnnsoftware Dnn.Platform < 10.1.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.