External risk intelligence

DNN Prompt Module Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-59545

DNN (DotNetNuke) is a web content management platform typically deployed as a public-facing web application. Since the vulnerable component is part of the CMS web interface, it is commonly accessible via the internet as part of the normal operation of a public website.

Cross-site Scripting

Dnnsoftware Dotnetnuke

before 10.1.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in the DNN (DotNetNuke) web content management platform, a widely used system within the Microsoft ecosystem. The issue allows for the execution of malicious commands, potentially leading to script execution and compromise of web content displayed to users. The primary concern is to confirm if your organization utilizes this platform and is exposed to this risk.

  • Vulnerability allows malicious commands in a web platform.
  • Confirms relevance and exposure for leadership awareness.
  • Understand platform usage; assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target the Prompt module within the DNN content management system to inject malicious input that, when processed by specific commands, leads to the execution of raw HTML. This could result in cross-site scripting (XSS) attacks, potentially compromising user sessions or injecting unwanted content, even if the input is otherwise sanitized for display.

  • Requires logged-in user access.
  • Vulnerable Prompt module commands.
  • Potential for script execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary scripts within a user's browser when they interact with a vulnerable DNN installation. This occurs because the Prompt module may not properly sanitize malicious input before processing certain commands, leading to script execution in the context of the user's session.

  • Raw HTML and script execution.
  • Malicious input processed by module commands.
  • Cross-site scripting (XSS) attacks.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects DNN (DotNetNuke) installations, specifically the Prompt module. Given its nature as a web content management platform, primary responsibility likely falls to the application owners or platform teams managing the DNN instances. The initial action should be to identify all DNN deployments, confirm their internet reachability and business criticality, and then engage the accountable teams to prioritize and plan remediation based on the assessed risk.

  • Application or Platform owners must take ownership.
  • Verify internet-facing DNN deployments' reachability.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DNN (DotNetNuke)?

DNN is an open-source web content management platform built on the Microsoft .NET framework. It is used by organizations to build, manage, and scale websites and web applications, providing tools to organize content and user permissions within the Microsoft ecosystem.

What does CVE-2025-59545 mean for the Prompt module?

This vulnerability is classified as Improper Neutralization of Input During Web Page Generation, commonly known as Cross-Site Scripting (XSS) or CWE-79. It occurs because the Prompt module fails to adequately sanitize specific commands, allowing raw HTML or scripts to be executed by a user's browser.

How is this XSS triggered in DNN?

An attacker must supply malicious input to the Prompt module that the system subsequently processes through vulnerable commands. Importantly, simple storage of content elsewhere is not enough; the bug specifically requires the input to be passed through these problematic command functions to trigger the script execution.

Do I need to worry if my DNN site is internal?

Halo Surface Signal indicates that DNN is typically deployed as a public-facing web application, making internet-accessible instances a primary concern. If your deployment is restricted to an internal network, the potential for unauthorized external access is reduced, but the risk remains if an authenticated user could be manipulated into triggering the payload.

When should I upgrade my DNN version?

If you are running any version of DNN prior to 10.1.0, you are affected by this vulnerability. You should prioritize planning an upgrade to version 10.1.0 or later to patch the Prompt module. Engage your application administration team immediately to verify your current version and schedule the necessary maintenance window.

References