Executive brief
DNN (formerly DotNetNuke) versions 9.2 through 9.2.1 utilize a weak encryption algorithm to protect input parameters. This vulnerability can lead to inadequate encryption strength, potentially allowing for unauthorized access to sensitive information or remote code execution via cookie deserialization.
Affected products
- DNN Software DotNetNuke (DNN) 9.2 through 9.2.1
Timeline
- 2019-07-03: disclosed: NVD Published Date
- 2020-04-02: other: Public exploit for cookie deserialization RCE released on Packet Storm
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog