HIGH8.8
GHSA-4qf5-7xc2-wqpg
DNN Path Traversal via Zip Slip
Quick fix
GHSA-4qf5-7xc2-wqpg — DotNetNuke.Core: upgrade to the fixed version with the command below.
dotnet add package DotNetNuke.Core --version 9.5.0Details
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal via unsafe handling of zip files
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DotNetNuke.Core
Introduced in:
0Fixed in: 9.5.0Fix
dotnet add package DotNetNuke.Core --version 9.5.0References
- https://nvd.nist.gov/vuln/detail/CVE-2020-5187[ADVISORY]
- https://github.com/dnnsoftware/Dnn.Platform/releases[WEB]
- https://medium.com/@SajjadPourali/dnn-dotnetnuke-cms-not-as-secure-as-you-think-e8516f789175[WEB]
- http://packetstormsecurity.com/files/156489/DotNetNuke-CMS-9.4.4-Zip-Directory-Traversal.html[WEB]