CVE-2018-18325 - DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
Project:DotNetNuke (DNN)
Product:DotNetNuke (DNN)
Date Added:2021-11-03Due Date:2022-05-03
Vulnerability Name
DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability
Description
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply updates per vendor instructions.
Additional Notes
https://nvd.nist.gov/vuln/detail/CVE-2018-18325