CVE-2016-7119
medium
CVSS v3
5.4
CVSS v2
3.5
VIR risk
5.4
Description
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN)
Predictions
Exploit likelihood
64%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.dnnsoftware.com/community/security/security-center
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | DotNetNuke.Core | <8.0.1 | 8.0.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| dnnsoftware | dotnetnuke | {"endIncluding":"08.00.04"} | |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.