{"id":"GHSA-2374-6cvw-qmx6","summary":"DNN CKEditor Provider allows unauthenticated upload out-of-the-box","details":"### Summary\nThe out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations.\n\n### Details\nThe new out-of-box experience blocks that endpoint to unauthenticated users. If there is a real need for the implementation to allow unauthenticated uploads, then the web.config can be edited by the implementer to remove that block and open the endpoint to the public.","aliases":["CVE-2025-62802"],"modified":"2025-10-29T21:59:04.747050Z","published":"2025-10-29T21:44:28Z","database_specific":{"github_reviewed_at":"2025-10-29T21:44:28Z","nvd_published_at":"2025-10-28T22:15:38Z","cwe_ids":["CWE-434"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-2374-6cvw-qmx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62802"},{"type":"WEB","url":"https://github.com/dnnsoftware/Dnn.Platform/commit/6497d3c35217e6e62e50d3ed7c8809eb69e3d06b"},{"type":"PACKAGE","url":"https://github.com/dnnsoftware/Dnn.Platform"}],"affected":[{"package":{"name":"Dnn.Platform","ecosystem":"NuGet","purl":"pkg:nuget/Dnn.Platform"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.1.1"}]}],"versions":["7.2.0","7.3.0","7.4.0","8.0.0","9.1.0","9.2.0","9.4.0","9.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-2374-6cvw-qmx6/GHSA-2374-6cvw-qmx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}