Intel

AIKIDO-2026-732530

DotNetNuke.Core is vulnerable to Code Injection

Code InjectionGHSA-hxc3-xv8x-w2g3 Published 6 days ago

80

High Risk

This Affects:

DOTNETDotNetNuke.Core
0.0.1 - 10.3.2
Fixed in 10.3.3
Are you affected? Scan for Free

TL;DR

Theme (skin) management incorporates administrator-supplied content into server-side resources without safe validation. A portal administrator can craft theme content that is compiled or executed as code on the server. Under certain deployment configurations this yields arbitrary code execution, compromising the installation including other portals in multi-portal setups. The fix validates administrator-supplied theme content before it is used server-side.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

DotNetNuke.Core is vulnerable to Code Injection in versions 0.0.1 - 10.3.2.

How to fix this

Upgrade the DotNetNuke.Core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform