Information Exposure Affecting dotnetnuke.core package, versions [9.5.0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.24% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-DOTNETNUKECORE-564444
  • published6 Apr 2020
  • disclosed6 Apr 2020
  • creditConnor Neff

Introduced: 6 Apr 2020

CVE-2020-11585  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for DotNetNuke.Core.

Overview

DotNetNuke.Core is a references provider to the DotNetNuke.dll to develop extensions for the DNN Platform.

Affected versions of this package are vulnerable to Information Exposure. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g. by using an arbitrary small integer value in the fileIds parameter.

References

CVSS Base Scores

version 3.1