{"id":"GHSA-5whq-j5qg-wjvp","summary":"Stored Cross-Site Scripting vulnerability in admin component of DotNetNuke","details":"Cross-site scripting (XSS) is possible in DNN (formerly DotNetNuke) before 9.4.0 by remote authenticated users via the Display Name field in the admin notification function.","aliases":["CVE-2019-12562"],"modified":"2024-02-16T05:19:14.742033Z","published":"2019-11-18T17:16:06Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-11-18T14:39:24Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-12562"},{"type":"WEB","url":"https://mayaseven.com/cve-2019-12562-stored-cross-site-scripting-in-dotnetnuke-dnn-version-v9-3-2"},{"type":"WEB","url":"http://packetstormsecurity.com/files/154673/DotNetNuke-Cross-Site-Scripting.html"}],"affected":[{"package":{"name":"DotNetNuke.Core","ecosystem":"NuGet","purl":"pkg:nuget/DotNetNuke.Core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.4.0"}]}],"versions":["6.0.0","7.0.0","7.0.6.121","7.1.0","7.1.2","7.2.0.613","7.3.0.499","7.3.1.20","7.4.0.353","7.4.1.280","7.4.2.216","8.0.0.809","8.0.1.239","8.0.2.4","8.0.3.5","8.0.4.226","9.0.0.1002","9.0.1.142","9.1.0.367","9.1.1.129","9.2.0.366","9.2.1.533","9.3.0","9.3.1","9.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/11/GHSA-5whq-j5qg-wjvp/GHSA-5whq-j5qg-wjvp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}