CVE-2018-15811: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Other sources
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15811?
CVE-2018-15811 is considered a medium severity vulnerability due to its potential to compromise sensitive data.
How do I fix CVE-2018-15811?
To fix CVE-2018-15811, update to DotNetNuke version 9.3 or later where the encryption algorithm has been strengthened.
What systems are affected by CVE-2018-15811?
CVE-2018-15811 affects DotNetNuke versions 9.2 through 9.2.1.
What type of vulnerability is CVE-2018-15811?
CVE-2018-15811 is an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm.
Can CVE-2018-15811 lead to data breaches?
Yes, CVE-2018-15811 can potentially lead to data breaches if exploited, as it may allow unauthorized access to sensitive data.