MEDIUM6.5
GHSA-vjcm-j85r-7p68
DNN File Upload Vulnerability
Details
DNN (formerly DotNetNuke) through 9.4.4 has a File upload vulnerability via bypassing client-side file extension check
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/DotNetNuke.Core
Introduced in:
0No fixed version published yet for DotNetNuke.Core (nuget). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-5188[ADVISORY]
- https://github.com/dnnsoftware/Dnn.Platform[PACKAGE]
- https://github.com/dnnsoftware/Dnn.Platform/releases[WEB]
- https://medium.com/@SajjadPourali/dnn-dotnetnuke-cms-not-as-secure-as-you-think-e8516f789175[WEB]
- http://packetstormsecurity.com/files/156484/DotNetNuke-CMS-9.5.0-File-Extension-Check-Bypass.html[WEB]