PT-2009-2569 · Dnn · Dotnetnuke

Published

2009-08-27

·

Updated

2017-08-17

·

CVE-2008-7100

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DotNetNuke versions 4.4.1 through 4.8.4
Description The issue allows remote authenticated users to bypass authentication and gain privileges. This is related to a "unique id" for user actions and improper validation of a user identity.
Recommendations For versions 4.4.1 through 4.8.4, update to a version that fixes the issue, as the current version allows for authentication bypass and privilege escalation due to improper validation of the user identity.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-7100

Affected Products

Dotnetnuke