CVE-2018-18325: DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Other sources
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18325?
CVE-2018-18325 has a high severity due to its weak encryption algorithm potentially leading to sensitive data exposure.
How do I fix CVE-2018-18325?
To fix CVE-2018-18325, upgrade DotNetNuke to a version later than 9.2.2 where the encryption issue has been resolved.
What are the risks associated with CVE-2018-18325?
The risks associated with CVE-2018-18325 include unauthorized access to user data and potential exploitation through the weak encryption.
What versions of DotNetNuke are affected by CVE-2018-18325?
CVE-2018-18325 affects DotNetNuke versions 9.2 through 9.2.2.
Is CVE-2018-18325 related to any other vulnerabilities?
Yes, CVE-2018-18325 is related to CVE-2018-15811 due to an inadequate fix for the same encryption issue.