First published: Mon Feb 24 2020(Updated: )
DNN (formerly DotNetNuke) through 9.4.4 has a File upload vulnerability via bypassing client-side file extension check
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/DotNetNuke.Core | <=9.4.4 | |
DNN (DotNetNuke) | <=9.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5188 is a vulnerability in DNN (formerly DotNetNuke) through 9.4.4 that allows an attacker to bypass client-side file extension checks during file uploads.
CVE-2020-5188 has a severity score of 6.5, which is considered medium.
CVE-2020-5188 affects DNN (formerly DotNetNuke) versions up to and including 9.4.4.
The CWE ID for CVE-2020-5188 is CWE-434.
To fix CVE-2020-5188, update DNN (formerly DotNetNuke) to a version that is not vulnerable, such as version 9.4.5 or higher.