← Vulnerability feed

Vulnerability record · CVE-2015-2794 · published 6 February 2017

CVE-2015-2794: DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeover

DDnnsoftware · Dotnetnuke

The installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application. Because the wizard is not protected after setup, a remote attacker can rerun it and take over the site. This is a critical access-control failure that grants full administrative control of the platform.

9.8 CVSS 3.0 Critical EPSS 75% · top 0.5% CWE-264 · Permissions and access controls
9.8CVSS 3.0 base score, v2 7.5
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote reinstall leading to SuperUser takeover with a CVSS 3.0 score of 9.8 and very high EPSS, plus a public exploit.

What it is

The installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application. Because the wizard is not protected after setup, a remote attacker can rerun it and take over the site. This is a critical access-control failure that grants full administrative control of the platform.

Impact

An attacker gains SuperUser access to the DNN instance, allowing full control of site content, configuration and hosted data. Depending on the deployment, this can lead to further compromise of the underlying host or connected systems.

Attack surface

Reached over the network by a direct HTTP request to Install/InstallWizard.aspx. The CVSS vector shows no privileges and no user interaction required, so the request can be sent directly by an unauthenticated attacker.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.74552, 99.47th percentile) and a public Exploit-DB entry (39777) exists, indicating known public exploitation techniques. No ransomware group usage is documented in the record.

What to do

  • Upgrade DotNetNuke to 7.4.1 or later, which is the fixed release per the vendor security center.
  • If immediate upgrade is not possible, apply the vendor workaround to block or remove access to Install/InstallWizard.aspx.
  • Restrict or block external access to the /Install/ path at the web server or WAF until patched.
  • Verify the installation wizard is disabled or removed after setup and confirm no residual installer files remain.
  • Review DNN SuperUser accounts and logs for unauthorized creation or changes after exposure.

Detection

  • Monitor web logs for requests to Install/InstallWizard.aspx, especially from external or unexpected source IPs.
  • Alert on creation of new SuperUser or administrative accounts in DNN, particularly outside change windows.
  • Look for POST requests to the install path followed by administrative actions or configuration changes.
  • Correlate any installer-path access with subsequent authentication events or file changes on the DNN host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2794 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9822DNN (DotNetNuke) cookie deserialization remote code executionDNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) rea…KEVEPSS 95%analysed7.5CVE-2018-15811DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data t…KEVEPSS 76%analysed7.5CVE-2018-18325DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for C…KEVEPSS 74%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 45%9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%8.8CVE-2020-5187Dnnsoftware dotnetnuke path traversal vulnerabilityDNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2015-2794), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.