CVE-2025-32374 - Medium Severity Vulnerability
Vulnerable Libraries - DotNetNuke-9.2.1.533.dll, dotnetnuke.core.9.2.1.533.nupkg
DotNetNuke-9.2.1.533.dll
DotNetNuke
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/lib/net40/DotNetNuke.dll
Dependency Hierarchy:
- ❌ DotNetNuke-9.2.1.533.dll (Vulnerable Library)
dotnetnuke.core.9.2.1.533.nupkg
DNN Platform is an open source web application framework.
This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg
Dependency Hierarchy:
- ❌ dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
Vulnerability Details
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.
Publish Date: 2025-04-09
URL: CVE-2025-32374
CVSS 3 Score Details (5.9)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-vc6j-mcqj-rgfp
Release Date: 2025-04-09
Fix Resolution: DotNetNuke.Core - 9.13.8,DotNetNuke.Core - 9.13.8
Step up your Open Source Security Game with Mend here
CVE-2025-32374 - Medium Severity Vulnerability
DotNetNuke-9.2.1.533.dll
DotNetNuke
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/lib/net40/DotNetNuke.dll
Dependency Hierarchy:
dotnetnuke.core.9.2.1.533.nupkg
DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to vulnerable library: /Modules/CloudFlareClearCache/packages/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg
Dependency Hierarchy:
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.
Publish Date: 2025-04-09
URL: CVE-2025-32374
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-vc6j-mcqj-rgfp
Release Date: 2025-04-09
Fix Resolution: DotNetNuke.Core - 9.13.8,DotNetNuke.Core - 9.13.8
Step up your Open Source Security Game with Mend here