DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
Vendor: DotNetNuke (DNN)
Product: DotNetNuke (DNN)
Added: 2021-11-03
Due Date: 2022-05-03
Description:
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Required Action:
Apply updates per vendor instructions.
CWEs: