CVE-2025-52487 - High Severity Vulnerability
Vulnerable Library - DotNetNuke-9.2.1.533.dll
DotNetNuke
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/lib/net40/DotNetNuke.dll
Dependency Hierarchy:
- ❌ DotNetNuke-9.2.1.533.dll (Vulnerable Library)
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
Vulnerability Details
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.
Publish Date: 2025-06-21
URL: CVE-2025-52487
CVSS 3 Score Details (8.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
CVE-2025-52487 - High Severity Vulnerability
DotNetNuke
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/lib/net40/DotNetNuke.dll
Dependency Hierarchy:
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.
Publish Date: 2025-06-21
URL: CVE-2025-52487
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here