Intel

AIKIDO-2026-273000

DotNetNuke.Core is vulnerable to Improper Authorization

Improper AuthorizationGHSA-56m6-r25g-78x6 Published 6 days ago

71

High Risk

This Affects:

DOTNETDotNetNuke.Core
0.0.1 - 10.3.2
Fixed in 10.3.3
Are you affected? Scan for Free

TL;DR

The content approval workflow does not consistently enforce authorization during state transitions. A user with permission to create or edit content can transition their own content to a published state, bypassing the configured approval step that requires a separate authorized approver. This publishes unreviewed content and undermines editorial oversight controls. The fix enforces workflow authorization on state transitions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use content approval workflows.

Background info

DotNetNuke.Core is vulnerable to Improper Authorization in versions 0.0.1 - 10.3.2.

How to fix this

Upgrade the DotNetNuke.Core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform