ZeroHour

CVE-2025-64095

large

Unauthenticated File Upload and Overwrite in DNN (DotNetNuke) CMS

CVSS 3.1
9.8 critical
EPSS
45%p99
Published
()
Modified
AI analysis

CVE-2025-64095 is an unauthenticated unrestricted file upload flaw (CWE-434) in the default HTML editor provider of DNN (formerly DotNetNuke), an open-source .NET web content management platform. Because the provider accepts uploads without authentication, any unauthenticated remote attacker can upload files and overwrite existing files, including images, with attacker-controlled content. This allows an attacker to deface a website by replacing its files and, combined with other issues, to inject cross-site-scripting (XSS) payloads; the CVSS 9.8 critical score reflects full network reachability with no privileges or user interaction required. All DNN deployments running any version prior to 10.1.1 are affected. Exploitation is not yet confirmed (not in CISA KEV, no public PoC known), but the EPSS score of 44.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

What to do: Upgrade DNN to version 10.1.1 or later as soon as possible. Until patched, restrict unauthenticated access to the HTML editor provider's upload endpoint (e.g., via authentication requirements or WAF/virtual-patching rules) and review existing uploaded images and site files for unexpected overwrites or injected XSS payloads.

Affected
dnnsoftware (DNN Corporation) DNN (DotNetNuke)all versions prior to 10.1.1 (fixed in 10.1.1)
Estimated exposure
largetens of thousands of internet-facing DNN sites (order 10k-100k) — Public technology-usage trackers show DNN in use on roughly tens of thousands of live websites and the vendor has historically claimed hundreds of thousands of cumulative deployments, so tens of thousands of internet-facing instances is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.

Vendors
dnnsoftware
Products
dotnetnuke
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.