PT-2009-2569 · Dnn · Dotnetnuke
Published
2009-08-27
·
Updated
2017-08-17
·
CVE-2008-7100
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DotNetNuke versions 4.4.1 through 4.8.4
Description
The issue allows remote authenticated users to bypass authentication and gain privileges. This is related to a "unique id" for user actions and improper validation of a
user identity.Recommendations
For versions 4.4.1 through 4.8.4, update to a version that fixes the issue, as the current version allows for authentication bypass and privilege escalation due to improper validation of the
user identity.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dotnetnuke