First published: Mon Feb 06 2017(Updated: )
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DNN (DotNetNuke) | <=07.04.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2794 has a medium severity level as it allows unauthorized reinstallation and SuperUser access.
To fix CVE-2015-2794, upgrade DotNetNuke to version 7.4.1 or later.
Exploiting CVE-2015-2794 can lead to unauthorized control over the application with SuperUser privileges.
CVE-2015-2794 affects all versions of DotNetNuke prior to 7.4.1.
Yes, the risk can be mitigated by restricting access to the Install/InstallWizard.aspx page.