CVE-2020-5188: Malicious File Upload
Published Feb 24, 2020
·Updated
DNN (formerly DotNetNuke) through 9.4.4 has a File upload vulnerability via bypassing client-side file extension check
Other sources
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
— MITRE
Affected Software
2 affected components
nuget/DotNetNuke.Core<=9.4.4
dnnsoftware Dotnetnuke<=9.4.4
Event History
Feb 24, 2020
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
05:09 PM
Frequently Asked Questions
1
What is CVE-2020-5188?
CVE-2020-5188 is a vulnerability in DNN (formerly DotNetNuke) through 9.4.4 that allows an attacker to bypass client-side file extension checks during file uploads.
2
How severe is CVE-2020-5188?
CVE-2020-5188 has a severity score of 6.5, which is considered medium.
3
What software versions are affected by CVE-2020-5188?
CVE-2020-5188 affects DNN (formerly DotNetNuke) versions up to and including 9.4.4.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-5188?
The CWE ID for CVE-2020-5188 is CWE-434.
5
How can I fix CVE-2020-5188?
To fix CVE-2020-5188, update DNN (formerly DotNetNuke) to a version that is not vulnerable, such as version 9.4.5 or higher.