Junglewise Threat Intelligence

CVE-2018-15811: Inadequate Encryption Strength in DotNetNuke

CVE-2018-15811 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2019-07-05

Technologies: Dotnetnuke (Dnn), DotNetNuke.Core (NuGet). Vendors: Dotnetnuke (Dnn), NuGet.

Executive brief

DNN (formerly DotNetNuke) versions 9.2 through 9.2.1 utilize a weak encryption algorithm to protect input parameters. This vulnerability can lead to inadequate encryption strength, potentially allowing for unauthorized access to sensitive information or remote code execution via cookie deserialization.

Affected products

  • DNN Software DotNetNuke (DNN) 9.2 through 9.2.1

Timeline

  • 2019-07-03: disclosed: NVD Published Date
  • 2020-04-02: other: Public exploit for cookie deserialization RCE released on Packet Storm
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats