{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T20:25:26.041","vulnerabilities":[{"cve":{"id":"CVE-2025-32371","sourceIdentifier":"security-advisories@github.com","published":"2025-04-09T16:15:24.933","lastModified":"2026-06-17T09:11:53.550","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is legitimate. This vulnerability is fixed in 9.13.4."},{"lang":"es","value":"DNN (anteriormente DotNetNuke) es una plataforma de gestión de contenido web (CMS) de código abierto del ecosistema de Microsoft. Se podía manipular una URL para el ImageHandler de DNN para representar el texto de un parámetro de cadena de consulta. Este texto se mostraría en la imagen resultante y un usuario que confiara en el dominio podría pensar que la información es legítima. Esta vulnerabilidad se corrigió en la versión 9.13.4."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"dnnsoftware","product":"Dnn.Platform","versions":[{"version":"< 9.13.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-09T15:40:06.851178Z","id":"CVE-2025-32371","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-451"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*","versionEndExcluding":"9.13.4","matchCriteriaId":"E7A63998-2CDE-487E-993A-F8C6FF497F5B"}]}]}],"references":[{"url":"https://github.com/dnnsoftware/Dnn.Platform/commit/5def7cc2e7931bb1041b21540bde99f96874a5a9","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2rrc-g594-rhqw","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}