GHSA-x8f7-h444-97w4

Suggest an improvement
Source
https://github.com/advisories/GHSA-x8f7-h444-97w4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-x8f7-h444-97w4/GHSA-x8f7-h444-97w4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x8f7-h444-97w4
Aliases
  • CVE-2015-2794
Published
2018-10-16T19:33:42Z
Modified
2024-12-02T06:04:56.253201Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
The installation wizard in DotNetNuke (DNN) allows privilege escalation
Details

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T22:02:45Z"
}
References

Affected packages

NuGet / DotNetNuke.Core

Package

Name
DotNetNuke.Core
View open source insights on deps.dev
Purl
pkg:nuget/DotNetNuke.Core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.4.1

Affected versions

6.*

6.0.0

7.*

7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353