CVE-2025-52485 | dnnsoftware Dnn.Platform up to 10.0.0 Activity Feed Attachments Endpoint cross site scripting (GHSA-wwc9-wmm3-2pmf / EUVD-2025-18803)
A vulnerability was found in dnnsoftware Dnn.Platform up to 10.0.0. It has been rated as problematic. Affected is an unknown function of the component Activity Feed Attachments Endpoint. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-52485. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.