Intel

AIKIDO-2025-10681

DotNetNuke.Instrumentation is vulnerable to Missing Authorization

Missing AuthorizationCVE-2025-64095 Published Oct 8, 2025

98

Critical Risk

This Affects:

dotnetDotNetNuke.Instrumentation
5.0.0 - 10.1.0
Fixed in 10.1.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an unauthenticated file upload issue in CKEditor. This vulnerability allows anonymous users to upload files through CKEditor endpoints, which should be restricted to authenticated users as a security measure. An attacker could exploit this weakness by uploading malicious files, such as scripts or executable content. It could potentially result in remote code execution, site defacement, or unauthorized data manipulation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

DotNetNuke.Instrumentation is vulnerable to Missing Authorization in versions 5.0.0 - 10.1.0.

How to fix this

Upgrade the DotNetNuke.Instrumentation library to the patch version.