Executive brief
DotNetNuke (DNN) versions 9.2 through 9.2.2 utilize a weak encryption algorithm to protect input parameters. This vulnerability is the result of an incomplete patch for CVE-2018-15811 and can lead to unauthorized information disclosure.
Affected products
- DNN Software DotNetNuke (DNN) 9.2 through 9.2.2
Timeline
- 2019-07-03: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog