CVE-2015-2794
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
The installation wizard in DotNetNuke (DNN) allows privilege escalation
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://dotnetnuke.codeplex.com/releases/view/615317
Vendor advisory: cve@mitre.org — http://www.dnnsoftware.com/community/security/security-center
Vendor advisory: cve@mitre.org — http://www.dnnsoftware.com/community-blog/cid/155198/workaround-for-potential-security-issue
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | DotNetNuke.Core | <7.4.1 | 7.4.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| dnnsoftware | dotnetnuke | {"endIncluding":"07.04.00"} | |
References
- http://www.dnnsoftware.com/community-blog/cid/155198/workaround-for-potential-security-issue
- http://www.dnnsoftware.com/community/security/security-center
- http://www.securityfocus.com/bid/96373
- https://dotnetnuke.codeplex.com/releases/view/615317
- https://www.exploit-db.com/exploits/39777/
- https://nvd.nist.gov/vuln/detail/CVE-2015-2794
- https://github.com/advisories/GHSA-x8f7-h444-97w4
- https://www.exploit-db.com/exploits/39777
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.