CVE-2020-5186 (Medium) detected in dotnetnuke.core.9.2.1.533.nupkg, dotnetnuke.core.9.6.1.nupkg #60
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-5186 - Medium Severity Vulnerability
Vulnerable Libraries - dotnetnuke.core.9.2.1.533.nupkg, dotnetnuke.core.9.6.1.nupkg
dotnetnuke.core.9.2.1.533.nupkg
DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg
Path to dependency file: /Modules/CloudFlareClearCache/Upendo.Modules.CloudFlareClearCache.csproj
Path to vulnerable library: /s/dotnetnuke.core/9.2.1.533/dotnetnuke.core.9.2.1.533.nupkg
Dependency Hierarchy:
dotnetnuke.core.9.6.1.nupkg
Provides basic references to the DotNetNuke.dll to develop extensions for the DNN Platform. For MVC or WebAPI please see other packages available as well
Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.6.1.nupkg
Path to dependency file: /Modules/CloudFlareClearCache/Upendo.Modules.CloudFlareClearCache.csproj
Path to vulnerable library: /s/dotnetnuke.core/9.6.1/dotnetnuke.core.9.6.1.nupkg,/home/wss-scanner/.nuget/packages/dotnetnuke.core/9.6.1/dotnetnuke.core.9.6.1.nupkg
Dependency Hierarchy:
Found in HEAD commit: e5ad080d6b4d66b3ca83faca2fd564a84b344f31
Found in base branch: master
Vulnerability Details
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
Publish Date: 2020-02-24
URL: CVE-2020-5186
CVSS 3 Score Details (5.4)
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: