QID 981691
QID 981691: Dotnet (nuget) Security Update for DotNetNuke.Core (GHSA-j3g9-6fx5-gjv7)
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j3g9-6fx5-gjv7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j3g9-6fx5-gjv7 -
github.com/advisories/GHSA-j3g9-6fx5-gjv7
CVEs related to QID 981691
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j3g9-6fx5-gjv7 | DotNetNuke.Core |
|