CVE-2025-32372

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. This vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. This vulnerability is fixed in 9.13.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*

History

26 Aug 2025, 00:46

Type Values Removed Values Added
CPE cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*
References () https://github.com/dnnsoftware/Dnn.Platform/commit/4721dd9eef846936d3b1a3676499e46968d15feb - () https://github.com/dnnsoftware/Dnn.Platform/commit/4721dd9eef846936d3b1a3676499e46968d15feb - Patch
References () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3f7v-qx94-666m - () https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3f7v-qx94-666m - Vendor Advisory
Summary
  • (es) DNN (anteriormente DotNetNuke) es una plataforma de gestión de contenido web (CMS) de código abierto del ecosistema de Microsoft. Se ha identificado una evasión para la vulnerabilidad CVE-2017-0929, previamente conocida, que permite a atacantes no autenticados ejecutar solicitudes GET arbitrarias contra los sistemas objetivo, incluyendo redes internas o adyacentes. Esta vulnerabilidad facilita un ataque SSRF semiciego, que permite a los atacantes hacer que el servidor objetivo envíe solicitudes a URL internas o externas sin ver las respuestas completas. Los posibles impactos incluyen el reconocimiento de la red interna y la evasión de firewalls. Esta vulnerabilidad se corrigió en la versión 9.13.8.
First Time Dnnsoftware
Dnnsoftware dotnetnuke

09 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-09 16:15

Updated : 2025-08-26 00:46


NVD link : CVE-2025-32372

Mitre link : CVE-2025-32372

CVE.ORG link : CVE-2025-32372


JSON object : View

Products Affected

dnnsoftware

  • dotnetnuke
CWE
CWE-918

Server-Side Request Forgery (SSRF)