A critical vulnerability in DNN (formerly DotNetNuke), one of the oldest open-source content management systems established in 2003.
The vulnerability, designated CVE-2025-52488, allows attackers to steal NTLM credentials through a sophisticated Unicode normalization bypass that exploits file system operations.
This authentication vulnerability affects the...