Intel

AIKIDO-2026-994815

DotNetNuke.Core is vulnerable to Missing Authorization

Missing AuthorizationGHSA-g8w5-h3rm-g8rj Published 6 days ago

75

High Risk

This Affects:

DOTNETDotNetNuke.Core
0.0.1 - 10.3.2
Fixed in 10.3.3
Are you affected? Scan for Free

TL;DR

The image processor does not consistently enforce DNN file and folder permissions when serving image files. Because authorization is not applied on the image retrieval path, an unauthenticated user can request and receive images stored in protected locations. This exposes image files intended to be restricted by permissions. The fix enforces file and folder authorization in the image processing path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you store images in folders with restricted permissions.

Background info

DotNetNuke.Core is vulnerable to Missing Authorization in versions 0.0.1 - 10.3.2.

How to fix this

Upgrade the DotNetNuke.Core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform