VulnerabilityModified
CVE-2015-2794
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
CRITICAL 9.8EPSS 74.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 74.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 74.55% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- dnnsoftware/dotnetnuke
- Source
- cve@mitre.org
References
- http://www.dnnsoftware.com/community-blog/cid/155198/workaround-for-potential-security-issueMitigation, Vendor Advisory
- http://www.dnnsoftware.com/community/security/security-centerPatch, Vendor Advisory
- http://www.securityfocus.com/bid/96373
- https://dotnetnuke.codeplex.com/releases/view/615317Release Notes, Vendor Advisory
- https://www.exploit-db.com/exploits/39777/Exploit, Third Party Advisory, VDB Entry
- http://www.dnnsoftware.com/community-blog/cid/155198/workaround-for-potential-security-issueMitigation, Vendor Advisory
- http://www.dnnsoftware.com/community/security/security-centerPatch, Vendor Advisory
- http://www.securityfocus.com/bid/96373
- https://dotnetnuke.codeplex.com/releases/view/615317Release Notes, Vendor Advisory
- https://www.exploit-db.com/exploits/39777/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.