Dotnetnuke < 10.3.3 Optional JavaScript restrictions for HTML module content (GHSA-mjq6-87j6-5f4g)

high Nessus Plugin ID 339554

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- The HTML module historically allowed trusted content editors to include JavaScript within HTML content. A new security option has been added to allow administrators to prevent executable scripts from being stored in HTML module content, reducing the risk of cross-site scripting (XSS) in environments where content editors are not fully trusted. The HTML module has traditionally permitted users with content editing permissions to create rich HTML content, including JavaScript. While this behavior is expected in many deployments where content editors are trusted, it may present a security risk in environments where content editing permissions are delegated to users who should not be permitted to execute client-side code. To improve deployment flexibility, DNN now includes an option to disallow JavaScript within HTML module content. New installations enable this protection by default. Existing installations retain their current behavior to preserve compatibility, but administrators are encouraged to evaluate enabling the new setting if content editors are not intended to publish executable scripts. This enhancement provides an additional layer of defense against cross-site scripting (XSS) while allowing administrators to choose the behavior that best fits their site's trust model. (GHSA-mjq6-87j6-5f4g)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?ee0fb6a6

Plugin Details

Severity: High

ID: 339554

File Name: dotnetnuke_GHSA-mjq6-87j6-5f4g.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/26/2026

Updated: 8/26/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026