Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
References
| Link | Resource |
|---|---|
| http://www.dnnsoftware.com/community/security/security-center | Patch Vendor Advisory |
| http://www.securityfocus.com/bid/92719 | |
| http://www.dnnsoftware.com/community/security/security-center | Patch Vendor Advisory |
| http://www.securityfocus.com/bid/92719 |
Configurations
History
24 Apr 2026, 17:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* | |
| First Time |
Dnnsoftware dotnetnuke
Dnnsoftware |
21 Nov 2024, 02:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.dnnsoftware.com/community/security/security-center - Patch, Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/92719 - |
Information
Published : 2016-08-31 14:59
Updated : 2026-05-06 22:30
NVD link : CVE-2016-7119
Mitre link : CVE-2016-7119
CVE.ORG link : CVE-2016-7119
JSON object : View
Products Affected
dnnsoftware
- dotnetnuke
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
