Your question has been submitted and is awaiting moderation.
Thank you for reporting this content, moderators have been notified of your submission.
Hi,
I'm trying to provide a client with some documentation or a recommendation regarding an XSS vulnerability found by doing a PCI compliance scan. The DNN version is 5.3.1 and the vulnerability details are as follows:
Reflected Cross-Site Scripting (XSS) vulnerability
URL: /Default.aspx
Parameter: categoryid
Request: /Default.aspx?categoryid=%3Cscript%3Ealert('TK00000011')%3C/script%3E
Any help or insight is appreciated. Thanks!