CVE-2018-15811

HIGH KEV NUCLEI

Dnnsoftware Dotnetnuke < 9.2.1 - Weak Encryption

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2018-15811 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including Jon Park, Jon Seigel, including a Metasploit module exploits/windows/http/dnn_cookie_deserialization_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC by crafting a malicious DNNPersonalization cookie, leading to remote code execution. It supports multiple versions with varying encryption requirements and includes features for key/IV extraction and payload encryption.

Description

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Exploits (2)

metasploit WORKING POC EXCELLENT
by Jon Park, Jon Seigel · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/dnn_cookie_deserialization_rce.rb

This Metasploit module exploits a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC by crafting a malicious DNNPersonalization cookie, leading to remote code execution. It supports multiple versions with varying encryption requirements and includes features for key/IV extraction and payload encryption.

Classification
Working Poc 100%
Attack Type
Deserialization
Complexity
Complex
Reliability
Reliable
Target: DotNetNuke (DNN) 5.0.0 to 9.3.0-RC
No auth needed
Prerequisites: Target must handle 404 errors with DNN's built-in error page · For versions 9.2.0+, encryption key/IV or verification code may be required
devstral-2 · analyzed Apr 24, 2026 Full analysis →
exploitdb WORKING POC
rubyremotewindows
https://www.exploit-db.com/exploits/48336

This Metasploit module exploits a deserialization vulnerability in DotNetNuke (DNN) versions 5.0.0 to 9.3.0-RC by crafting a malicious DNNPersonalization cookie, leading to remote code execution. The exploit leverages the ObjectStateFormatter deserialization mechanism and includes encryption support for newer DNN versions.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: DotNetNuke (DNN) 5.0.0 to 9.3.0-RC
No auth needed
Prerequisites: Target must be running a vulnerable version of DNN · DNN must be configured to handle 404 errors with its built-in error page
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization
HIGHVERIFIEDby pdteam
FOFA: app="dotnetnuke"

Scores

CVSS v3 7.5
EPSS 0.9296
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-0590
CWE
CWE-326
Status published
Products (2)
dnnsoftware/dotnetnuke 9.2 - 9.2.1
nuget/DotNetNuke.Core 9.2.0 - 9.2.2NuGet
Published Jul 03, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026