DotNetNuke.Core is vulnerable to Improper Authorization
69
Medium Risk
Module access control does not consistently honor explicit module-level restrictions when a user holds broader page-level permissions. Explicit restrict settings on individual modules are not enforced, so a user with page permissions can reach modules an administrator restricted. This can expose administrative or restricted module functionality. The fix enforces module-level access restrictions independently of page-level permissions.
You are affected if you are using a version that falls within the vulnerable range and you rely on module-level restrictions that are tighter than page-level permissions.
DotNetNuke.Core is vulnerable to Improper Authorization in versions 0.0.1 - 10.3.2.
Upgrade the DotNetNuke.Core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.