Cross-Site Scripting Vulnerability in DNN Platform Prompt Module
CVE-2025-59545
9.1CRITICAL
What is CVE-2025-59545?
The Prompt module in DNN Platform, an open-source content management system, is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows attackers to execute arbitrary commands that can return raw HTML. Despite efforts to sanitize input for display in other contexts, malicious scripts can still bypass these measures when handled through specific commands, posing significant security risks to users. The vulnerability has been addressed in version 10.1.0, highlighting the importance of maintaining up-to-date software to protect against potential threats.
Affected Version(s)
Dnn.Platform < 10.1.0