← Vulnerability feed

Vulnerability record · CVE-2018-15811 · published 3 July 2019

CVE-2018-15811: DNN (DotNetNuke) weak encryption of input parameters

DDnnsoftware · Dotnetnuke

DNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data that the product intends to keep confidential can be recovered or manipulated by an attacker who can observe or supply those parameters. The record does not name the specific algorithm or the exact parameters involved.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 76% · top 0.5% CWE-326 · Inadequate encryption strength
7.5CVSS 3.1 base score, v2 5.0
76%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityThe flaw is in CISA KEV with a past remediation due date and an EPSS score above the 99th percentile, so it should be treated as actively exploited.

What it is

DNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data that the product intends to keep confidential can be recovered or manipulated by an attacker who can observe or supply those parameters. The record does not name the specific algorithm or the exact parameters involved.

Impact

An attacker can read or tamper with parameter data that DNN intended to protect with encryption, leading to confidentiality loss. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.

Attack surface

The flaw is reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed DNN 9.2 to 9.2.1 endpoint that accepts these encrypted input parameters is in scope.

Exploitation

CVE-2018-15811 is listed in CISA KEV with a due date of 2022-05-03, and EPSS gives a 30-day probability of 0.74048 (99.458th percentile), indicating active exploitation is expected. A Packet Storm reference tagged Exploit points to a DotNetNuke cookie deserialization remote code execution write-up, though the record does not state that this CVE is the exact flaw in that exploit.

What to do

  • Upgrade DNN to a release after 9.2.1 per the vendor security center and release notes; this is the primary fix.
  • If immediate upgrade is not possible, restrict network access to DNN instances so only trusted clients can reach parameter-handling endpoints.
  • Review and rotate any secrets or keys used by the weak parameter encryption, since exposure may already have occurred.
  • Monitor vendor advisories for DNN 9.2.x for any backported fix or additional guidance.

Detection

  • Inspect DNN request logs for repeated or anomalous submissions of encrypted parameters from single sources.
  • Alert on attempts to decode or replay DNN parameter values, including malformed or truncated ciphertext.
  • Correlate DNN access logs with known exploitation indicators from the Packet Storm cookie deserialization write-up.
  • Track outbound or lateral activity from DNN hosts that could follow parameter disclosure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-15811 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15811 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9822DNN (DotNetNuke) cookie deserialization remote code executionDNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) rea…KEVEPSS 95%analysed7.5CVE-2018-18325DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for C…KEVEPSS 74%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 45%9.8CVE-2015-2794DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeoverThe installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application.…EPSS 75%analysed9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%8.8CVE-2020-5187Dnnsoftware dotnetnuke path traversal vulnerabilityDNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2018-15811), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.