CVE-2017-0929
High severity vulnerability that affects DotNetNuke.Core
Record summary
CVE-2017-0929 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DotNetNuke (DNN)Browse dnnsoftware / DotNetNuke (DNN) | VulnCheck | Version data not supplied | |
DotNetNuke.CoreBrowse NuGet / DotNetNuke.Core | GitHub Advisory | Before 9.2.0 · Fixed in 9.2.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHDotNetNuke (DNN) ImageHandler <9.2.0 - Server-Side Request ForgeryCVSS 7.5
DotNetNuke (aka DNN) before 9.2.0 suffers from a server-side request forgery vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
Impact
An attacker can exploit this vulnerability to bypass security controls, access internal resources, and potentially perform further attacks.
Remediation
Upgrade DotNetNuke (DNN) ImageHandler to version 9.2.0 or above.
Source: ProjectDiscovery