DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- < 10.1.1
A file upload vulnerability has been identified in DNN (formerly DotNetNuke) versions prior to 10.1.1. The issue arises in the default HTML editing experience, which allows unauthenticated users to upload files. This capability could lead to additional security problems and is unnecessary for most implementations. The vulnerability has been addressed in version 10.1.1.
Exploitation of this vulnerability allows unauthenticated users to upload files, which could be leveraged for further security issues.
Users can upgrade to DNN version 10.1.1 or later to address this vulnerability. If there is a specific need to allow unauthenticated file uploads in an earlier version, the web.config file can be modified to remove the default upload block.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.