{"advisories":[{"id":"GHSA-mgfv-2362-jq96","source":"ghsa","title":"DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input","url":"https://github.com/advisories/GHSA-mgfv-2362-jq96"}],"cve":"CVE-2025-52488","epss":{"score":0.35761},"mitre":{"cpes":[],"created":"2025-06-21T02:51:25.252000+00:00","description":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.6,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2025/52xxx/CVE-2025-52488.json","references":["https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96"],"title":"DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input","updated":"2025-06-23T17:47:24.661000+00:00","vendors":[],"weaknesses":["CWE-200"]},"nvd":{"cpes":["cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*"],"created":"2025-06-21T03:15:24.817000+00:00","description":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.6,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2025/CVE-2025-52488.json","references":["https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96"],"title":null,"updated":"2026-06-17T09:36:35.260000+00:00","vendors":["dnnsoftware","dnnsoftware$PRODUCT$dotnetnuke"],"weaknesses":["CWE-200","NVD-CWE-noinfo"]},"opencve":{"changes":[{"created":"2025-06-21T03:00:00+00:00","data":[{"details":{"new":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.","old":null},"type":"description"},{"details":{"new":"DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input","old":null},"type":"title"},{"details":{"added":["CWE-200"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.6,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"f86462f6-650e-40dd-879c-96906c366c6c"},{"created":"2025-06-23T18:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"dccd63c5-d7aa-4ea3-8605-4f6439972e26"},{"created":"2025-07-14T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.08839},"old":{"score":0.00041}}}},"type":"metrics"}],"id":"ee4e52a7-4017-4a74-9e70-6ce90b3ad5ef"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.12555},"old":{"score":0.08839}}}},"type":"metrics"}],"id":"1e337a1d-8ed1-4957-b5aa-e76927697b43"},{"created":"2025-09-15T15:30:00+00:00","data":[{"details":["dnnsoftware","dnnsoftware$PRODUCT$dotnetnuke"],"type":"first_time"},{"details":{"added":["NVD-CWE-noinfo"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["dnnsoftware","dnnsoftware$PRODUCT$dotnetnuke"],"removed":[]},"type":"vendors"}],"id":"874ccdc0-6948-463d-94ff-8066dfef7017"}],"cpes":{"data":["cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-06-21T02:51:25.252000+00:00","provider":"mitre"},"description":{"data":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.6,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.35761},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96"],"providers":["mitre","nvd"]},"title":{"data":"DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input","provider":"mitre"},"updated":{"data":"2025-09-15T15:21:56.380000+00:00","provider":"nvd"},"vendors":{"data":["dnnsoftware","dnnsoftware$PRODUCT$dotnetnuke"],"providers":["nvd"]},"weaknesses":{"data":["CWE-200","NVD-CWE-noinfo"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-06-21T02:51:25.252000+00:00","description":"DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input","updated":"2025-06-23T17:47:20.042000+00:00","vendors":[],"vulnrichment_repo_path":"2025/52xxx/CVE-2025-52488.json","weaknesses":[]}}