GHSA-2374-6cvw-qmx6

Suggest an improvement
Source
https://github.com/advisories/GHSA-2374-6cvw-qmx6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-2374-6cvw-qmx6/GHSA-2374-6cvw-qmx6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2374-6cvw-qmx6
Aliases
Published
2025-10-29T21:44:28Z
Modified
2025-10-29T21:59:04.747050Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
DNN CKEditor Provider allows unauthenticated upload out-of-the-box
Details

Summary

The out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations.

Details

The new out-of-box experience blocks that endpoint to unauthenticated users. If there is a real need for the implementation to allow unauthenticated uploads, then the web.config can be edited by the implementer to remove that block and open the endpoint to the public.

Database specific
{
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-434"
    ],
    "github_reviewed_at": "2025-10-29T21:44:28Z",
    "nvd_published_at": "2025-10-28T22:15:38Z",
    "github_reviewed": true
}
References

Affected packages

NuGet / Dnn.Platform

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.1

Affected versions

7.*

7.2.0
7.3.0
7.4.0

8.*

8.0.0

9.*

9.1.0
9.2.0
9.4.0
9.9.0