Intel

AIKIDO-2026-44955

DotNetNuke.Core is vulnerable to Authorization Bypass

Authorization BypassGHSA-fpr5-67pq-3hf5 Published 6 days ago

96

Critical Risk

This Affects:

DOTNETDotNetNuke.Core
0.0.1 - 10.3.2
Fixed in 10.3.3
Are you affected? Scan for Free

TL;DR

The user registration approval workflow does not verify administrative privileges before accepting an approval action. An authenticated non-administrative user can approve pending registrations by tampering with request parameters. On sites relying on administrator approval as a gate, this activates accounts and grants access to protected content without authorization. The fix enforces administrator authorization on the approval operation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you require administrator approval for new user registrations.

Background info

DotNetNuke.Core is vulnerable to Authorization Bypass in versions 0.0.1 - 10.3.2.

How to fix this

Upgrade the DotNetNuke.Core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform