DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in the allow list. This issue has been patched in version 10.0.1.
References
Link | Resource |
---|---|
https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-fjhg-3mrh-mm7h | Vendor Advisory |
Configurations
History
15 Sep 2025, 15:30
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dnnsoftware dotnetnuke
Dnnsoftware |
|
References | () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-fjhg-3mrh-mm7h - Vendor Advisory | |
CPE | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
23 Jun 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Jun 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-21 03:15
Updated : 2025-09-15 15:30
NVD link : CVE-2025-52487
Mitre link : CVE-2025-52487
CVE.ORG link : CVE-2025-52487
JSON object : View
Products Affected
dnnsoftware
- dotnetnuke
CWE
CWE-863
Incorrect Authorization