CVE-2025-32035
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.
Scoring
- Severity
- LOW
- CVSS base score
- 2.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-351
- Published
- 2025-04-08
- Last modified
- 2026-03-13
Affected products
- dnnsoftware Dnn.Platform
Weakness type
Related vulnerabilities
- CVE-2026-15305 — TYPO3 CMS - Unrestricted File Upload in Form Framework
- CVE-2025-31951 — HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability
- CVE-2026-41341 — OpenClaw < 2026.3.31 - Component Interaction Misclassification in Discord Extension
- CVE-2025-65960 — Contao is vulnerable to remote code execution in template closures
- CVE-2025-54413 — skops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-54412 — skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution
- CVE-2025-47939 — TYPO3 CMS Vulnerable to Unrestricted File Upload in File Abstraction Layer
- CVE-2025-30510 — Growatt Cloud portal Insufficient Type Distinction