GHSA-3m8r-w7xg-jqvw

Suggest an improvement
Source
https://github.com/advisories/GHSA-3m8r-w7xg-jqvw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-3m8r-w7xg-jqvw/GHSA-3m8r-w7xg-jqvw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3m8r-w7xg-jqvw
Aliases
Published
2025-10-29T21:48:52Z
Modified
2025-10-29T22:17:08.953314Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
Details

Summary

The default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files.

Description

An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-434"
    ],
    "github_reviewed_at": "2025-10-29T21:48:52Z",
    "nvd_published_at": "2025-10-28T22:15:38Z",
    "severity": "CRITICAL"
}
References

Affected packages

NuGet / DNN.PLATFORM

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.1

Affected versions

7.*

7.2.0
7.3.0
7.4.0

8.*

8.0.0

9.*

9.1.0
9.2.0
9.4.0
9.9.0