Junglewise Threat Intelligence

CVE-2018-18325: Inadequate Encryption Strength in DotNetNuke

CVE-2018-18325 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2019-07-05

Technologies: Dotnetnuke (Dnn), DotNetNuke.Core (NuGet). Vendors: Dotnetnuke (Dnn), NuGet.

Executive brief

DotNetNuke (DNN) versions 9.2 through 9.2.2 utilize a weak encryption algorithm to protect input parameters. This vulnerability is the result of an incomplete patch for CVE-2018-15811 and can lead to unauthorized information disclosure.

Affected products

  • DNN Software DotNetNuke (DNN) 9.2 through 9.2.2

Timeline

  • 2019-07-03: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats