HomeSecurityCritical vulnerability in DNN platform allows execution of malicious scripts

Critical vulnerability in DNN platform allows execution of malicious scripts

A critical cached cross-site scripting has emerged in the popular DotNetNuke (DNN), threatening websites running this widely used content management system.

The flaw, which is tracked as CVE-2025-59545 with a severity rating of 9.1 out of 10 , affects all versions of the DNN platform prior to version 10.1.0 and allows attackers to execute malicious scripts via the platform's Prompt module

See also: OnePlus: Vulnerability in OxygenOS allows apps to read SMS

DNN vulnerability

The flaw arises from the way DNN's Prompt module processes commands that return raw HTML. While the platform typically sanitizes data submitted by users before displaying it in input forms, the Prompt module bypasses these sanitization mechanisms by treating the command output as executable HTML. This creates a dangerous path for attackers to inject and execute malicious scripts in the trusted environment of the application.

The vulnerability poses significant risks to organizations operating affected DNN installations, particularly when exploited in superuser environments. Attackers could craft malicious input containing embedded scripts or malicious markup, which when processed via specific Prompt commands, would be displayed directly to browsers without appropriate security.

Github analysts discovered this critical vulnerability through extensive security research, highlighting the importance of continuously monitoring the platform for emerging threats. Attackers are exploiting this flaw by targeting the network-accessible Prompt module with relatively low-sophistication attack vectors. The exploit requires minimal privileges and user interaction, making it an attractive target for malicious actors seeking to compromise DNN-powered websites.

See also: Salesforce CLI Installer: Vulnerability allows malicious code execution

Critical vulnerability in DNN platform allows execution of malicious scripts

Once successfully exploited, the vulnerability could impact the confidentiality, integrity, and availability of the system in changing security contexts. The attack mechanism revolves around a fundamental design flaw in the way the Prompt module handles command execution and output rendering. When an attacker submits crafted input through the module, the system fails to distinguish between legitimate HTML output and malicious script content.

The vulnerability manifests when certain commands process untrusted data and return it as HTML, effectively bypassing the application's security boundaries. The attack follows a stored XSS pattern, categorized under vulnerability classification CWE-79. Malicious payloads can be stored permanently within the system and executed each time the compromised content is accessed. This persistence factor amplifies the impact of the vulnerability, as it affects not only the initial victim but also potentially all subsequent users who interact with the compromised content.

See also: CISA: Chrome zero-day vulnerability in KEV Catalog

Critical vulnerability in DNN platform allows execution of malicious scripts

Organizations using affected versions of the DNN platform should immediately upgrade to version 10.1.0, which includes comprehensive patches that address this critical security vulnerability.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS