DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/151304/DNN-9.1-XML-Related-Cross-Site-Scripting.html | exploit vdb entry third party advisory |
http://www.dnnsoftware.com/community/security/security-center | release notes vendor advisory |