CVE-2025-32035 - Low Severity Vulnerability
Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg
DNN Platform is an open source web application framework.
This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg
Dependency Hierarchy:
- ❌ dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
Vulnerability Details
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.
Publish Date: 2025-04-08
URL: CVE-2025-32035
CVSS 3 Score Details (2.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-8q89-mqw7-9pp7
Release Date: 2025-04-08
Fix Resolution: DotNetNuke.Core - 9.13.2,https://github.com/dnnsoftware/Dnn.Platform.git - v9.13.2
Step up your Open Source Security Game with Mend here
CVE-2025-32035 - Low Severity Vulnerability
DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg
Dependency Hierarchy:
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.
Publish Date: 2025-04-08
URL: CVE-2025-32035
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-8q89-mqw7-9pp7
Release Date: 2025-04-08
Fix Resolution: DotNetNuke.Core - 9.13.2,https://github.com/dnnsoftware/Dnn.Platform.git - v9.13.2
Step up your Open Source Security Game with Mend here