VulnerabilityModified
CVE-2008-7100
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."
MEDIUM 6.5EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- dnnsoftware/dotnetnuke
- Source
- cve@mitre.org
References
- http://osvdb.org/48343
- http://secunia.com/advisories/31893Vendor Advisory
- http://www.dotnetnuke.com/News/SecurityPolicy/Securitybulletinno21/tabid/1174/Default.aspxPatch, Vendor Advisory
- http://www.securityfocus.com/bid/31145Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45081
- http://osvdb.org/48343
- http://secunia.com/advisories/31893Vendor Advisory
- http://www.dotnetnuke.com/News/SecurityPolicy/Securitybulletinno21/tabid/1174/Default.aspxPatch, Vendor Advisory
- http://www.securityfocus.com/bid/31145Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45081
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.