First published: Wed Jul 03 2019(Updated: )
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DotNetNuke | ||
DNN (DotNetNuke) | >=9.2<=9.2.1 | |
>=9.2<=9.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15811 is considered a medium severity vulnerability due to its potential to compromise sensitive data.
To fix CVE-2018-15811, update to DotNetNuke version 9.3 or later where the encryption algorithm has been strengthened.
CVE-2018-15811 affects DotNetNuke versions 9.2 through 9.2.1.
CVE-2018-15811 is an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm.
Yes, CVE-2018-15811 can potentially lead to data breaches if exploited, as it may allow unauthorized access to sensitive data.