VDB
Sign up
HIGH7.5

GHSA-g8j6-m4p7-5rfq

High severity vulnerability that affects DotNetNuke.Core

Quick fix

GHSA-g8j6-m4p7-5rfq — DotNetNuke.Core: upgrade to the fixed version with the command below.

dotnet add package DotNetNuke.Core --version 9.2.0

Details

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/DotNetNuke.Core
Introduced in: 0Fixed in: 9.2.0
Fixdotnet add package DotNetNuke.Core --version 9.2.0

References