Dnn.Platform是Dnn Software开源的一个开源网络内容管理平台(CMS)。 Dnn.Platform 10.0.1之前版本存在信息泄露漏洞,该漏洞源于恶意交互暴露NTLM哈希,可能导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dnnsoftware | Dnn.Platform | >= 6.0.0, < 10.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-52488.yaml | POC Details |
| 2 | This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes through Unicode path normalization attacks. | https://github.com/SystemVll/CVE-2025-52488 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-52487 | DNN.PLATFORM possibly allows bypass of IP Filters | |
| CVE-2025-52486 | DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations w | |
| CVE-2025-52485 | DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed |
No comments yet