File Upload Vulnerability in DNN Web Content Management Platform
CVE-2025-62802

4.3MEDIUM

Key Information:

Vendor
CVE Published:
28 October 2025

What is CVE-2025-62802?

The DNN platform, a widely-used open-source web content management system, has a vulnerability that enables unauthenticated users to upload files in its HTML editing environment. This security flaw, present in versions prior to 10.1.1, poses a significant risk as it could lead to further exploitation and security breaches within the platform. It is recommended to upgrade to version 10.1.1 or later to mitigate this risk.

Affected Version(s)

Dnn.Platform < 10.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.