CISA Known Exploited Vulnerability

CVE-2018-15811

DotNetNuke (DNN) · DotNetNuke (DNN)

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Date added
BOD 22-01 due date
CWE CWE-326
Ransomware Unknown

CISA description

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

Required action

Apply updates per vendor instructions.