Skip to content

Known CVE

DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization

DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters because of an incomplete fix for CVE-2018-15811. This cryptographic weakness enables attackers to craft malicious DNNPersonalization cookies that can be deserialized, leading to remote code execution.

CVE-2018-18325

High2018CVSS 7.5CWE-326

cve2018 · dotnetnuke · crypto · deserialization · rce · kev · dnnsoftware · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website