{"id":"GHSA-v76m-f5cx-8rg4","summary":"Moderate severity vulnerability that affects DotNetNuke.Core","details":"Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","aliases":["CVE-2015-1566"],"modified":"2024-12-02T05:53:51.323130Z","published":"2018-10-16T19:33:25Z","database_specific":{"github_reviewed_at":"2020-06-16T21:57:07Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1566"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v76m-f5cx-8rg4"},{"type":"WEB","url":"http://secunia.com/advisories/62832"},{"type":"WEB","url":"http://www.dnnsoftware.com/platform/manage/security-center"}],"affected":[{"package":{"name":"DotNetNuke.Core","ecosystem":"NuGet","purl":"pkg:nuget/DotNetNuke.Core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4.0"}]}],"versions":["6.0.0","7.0.0","7.0.6.121","7.1.0","7.1.2","7.2.0.613","7.3.0.499","7.3.1.20"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-v76m-f5cx-8rg4/GHSA-v76m-f5cx-8rg4.json"}}],"schema_version":"1.9.0"}