Vulnerability record · CVE-2018-18325 · published 3 July 2019
CVE-2018-18325: DNN (DotNetNuke) weak encryption of input parameters
DDnnsoftware · Dotnetnuke
DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for CVE-2018-15811 was incomplete. Weak protection of parameters can let an attacker read or tamper with data the application assumes is confidential or trustworthy.
Description
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication or user interaction, has a high CVSS score, is in CISA KEV, and has very high EPSS probability with public exploit references.
What it is
DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for CVE-2018-15811 was incomplete. Weak protection of parameters can let an attacker read or tamper with data the application assumes is confidential or trustworthy.
Impact
An attacker can recover or manipulate protected input parameters, leading to disclosure of sensitive data and potentially enabling further attacks such as cookie deserialization remote code execution as referenced in public exploit material.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N; the flaw is in how the application encrypts input parameters.
Exploitation
It is listed in CISA KEV with a 2021-11-03 addition date, and EPSS shows a 30-day probability of 0.74048 (99.458th percentile); references include an Exploit-tagged Packet Storm entry for DotNetNuke cookie deserialization RCE.
What to do
- Upgrade DNN to a release newer than 9.2.2 that contains the complete fix for CVE-2018-15811 and this follow-up issue, per vendor instructions.
- If immediate upgrade is not possible, restrict network access to the DNN instance and place it behind authentication or a reverse proxy where feasible.
- Rotate any secrets, cookies, or tokens that may have been protected by the weak algorithm.
- Monitor vendor security advisories and release notes for DNN platform updates addressing this issue.
Detection
- Inspect DNN request and response traffic for tampered or replayed encrypted parameters, especially cookie values tied to deserialization.
- Alert on anomalous POST requests or cookie payloads to DNN endpoints that match known deserialization exploit patterns.
- Review web server and application logs for unexpected deserialization errors, exceptions, or process behavior on DNN hosts.
- Hunt for outbound connections or child processes spawned by the DNN application worker that are inconsistent with normal operation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-18325 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
| http://packetstormsecurity.com/files/157080/DotNetNuke-Cookie-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/dnnsoftware/Dnn.Platform/releases | Release Notes |
| https://www.dnnsoftware.com/community/security/security-center | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-18325 | US Government Resource |
Track CVE-2018-18325 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-18325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.