DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
| Software | From | Fixed in |
|---|---|---|
| dnnsoftware / dotnetnuke | - | 9.10.2.x |