Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 NuGet

The installation wizard in DotNetNuke (DNN) allows privilege escalation

GHSA-x8f7-h444-97w4 · CVE-2015-2794

Published · Modified

Description

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

Ready to move

Start Securing

Free, no credit card | First findings in minutes