← Vulnerability feed

Vulnerability record · CVE-2018-18325 · published 3 July 2019

CVE-2018-18325: DNN (DotNetNuke) weak encryption of input parameters

DDnnsoftware · Dotnetnuke

DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for CVE-2018-15811 was incomplete. Weak protection of parameters can let an attacker read or tamper with data the application assumes is confidential or trustworthy.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 74% · top 0.5% CWE-326 · Inadequate encryption strength
7.5CVSS 3.1 base score, v2 5.0
74%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication or user interaction, has a high CVSS score, is in CISA KEV, and has very high EPSS probability with public exploit references.

What it is

DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters, and the issue persists because the fix for CVE-2018-15811 was incomplete. Weak protection of parameters can let an attacker read or tamper with data the application assumes is confidential or trustworthy.

Impact

An attacker can recover or manipulate protected input parameters, leading to disclosure of sensitive data and potentially enabling further attacks such as cookie deserialization remote code execution as referenced in public exploit material.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N; the flaw is in how the application encrypts input parameters.

Exploitation

It is listed in CISA KEV with a 2021-11-03 addition date, and EPSS shows a 30-day probability of 0.74048 (99.458th percentile); references include an Exploit-tagged Packet Storm entry for DotNetNuke cookie deserialization RCE.

What to do

  • Upgrade DNN to a release newer than 9.2.2 that contains the complete fix for CVE-2018-15811 and this follow-up issue, per vendor instructions.
  • If immediate upgrade is not possible, restrict network access to the DNN instance and place it behind authentication or a reverse proxy where feasible.
  • Rotate any secrets, cookies, or tokens that may have been protected by the weak algorithm.
  • Monitor vendor security advisories and release notes for DNN platform updates addressing this issue.

Detection

  • Inspect DNN request and response traffic for tampered or replayed encrypted parameters, especially cookie values tied to deserialization.
  • Alert on anomalous POST requests or cookie payloads to DNN endpoints that match known deserialization exploit patterns.
  • Review web server and application logs for unexpected deserialization errors, exceptions, or process behavior on DNN hosts.
  • Hunt for outbound connections or child processes spawned by the DNN application worker that are inconsistent with normal operation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-18325 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-18325 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-9822DNN (DotNetNuke) cookie deserialization remote code executionDNN (DotNetNuke) before 9.1.1 deserializes attacker-controlled cookie data, allowing remote code execution. The flaw is a code injection (CWE-94) rea…KEVEPSS 95%analysed7.5CVE-2018-15811DNN (DotNetNuke) weak encryption of input parametersDNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. Because the protection is inadequate, data t…KEVEPSS 76%analysed10.0CVE-2006-3601Dnnsoftware dotnetnuke vulnerability** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileg…EPSS 2.5%9.8CVE-2025-64095Dnnsoftware dotnetnuke unrestricted file upload vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…EPSS 47%9.8CVE-2015-2794DotNetNuke install wizard allows unauthenticated reinstall and SuperUser takeoverThe installation wizard in DotNetNuke (DNN) before 7.4.1 can be reached directly at Install/InstallWizard.aspx and used to reinstall the application.…EPSS 75%analysed9.0CVE-2025-59545Dnnsoftware dotnetnuke cross-site scripting vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt mod…EPSS 0.49%8.8CVE-2025-52487Dnnsoftware dotnetnuke incorrect authorization vulnerabilityDNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…EPSS 0.35%8.8CVE-2020-5187Dnnsoftware dotnetnuke path traversal vulnerabilityDNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2018-18325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.