PT-2009-2569 · Dnn · Dotnetnuke
Publicado
2009-08-27
·
Atualizado
2017-08-17
·
CVE-2008-7100
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DotNetNuke versions 4.4.1 through 4.8.4
Description
The issue allows remote authenticated users to bypass authentication and gain privileges. This is related to a "unique id" for user actions and improper validation of a
user identity.Recommendations
For versions 4.4.1 through 4.8.4, update to a version that fixes the issue, as the current version allows for authentication bypass and privilege escalation due to improper validation of the
user identity.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dotnetnuke