CVE-2016-7119
31.08.2016, 14:59
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
Vendor | Product | Version |
---|---|---|
dotnetnuke | dotnetnuke | 𝑥 ≤ 08.00.04 |
𝑥
= Vulnerable software versions