PT-2020-10153 · Dnn+1 · Dnn+1

Published

2020-01-21

·

Updated

2020-02-05

·

CVE-2019-19392

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DNN (formerly DotNetNuke) forDNN.UsersExportImport module versions prior to 1.2.0
Description The issue allows an unprivileged user to import new users with Administrator privileges by including specific roles in XML or CSV data, such as Roles="Administrators".
Recommendations For versions prior to 1.2.0, update the forDNN.UsersExportImport module to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the user import functionality to prevent unauthorized creation of administrator accounts.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19392

Affected Products

Dnn
Fordnn.Usersexportimport