S4E just found a medium cve-2023-25727 scanner
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2017-9822 Scanner

Detects 'Deserialization of Untrusted Data' vulnerability in DotNetNuke CMS affects v. before 9.1.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2017-9822
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
DotNetNuke CMS Fixed in 9.1.1by DotNetNuke
DotNetNuke CMS Fixed in 9.1.1
Updated Aug 5, 2026View on NVD →
Detail

DotNetNuke (DNN) is a popular Content Management System (CMS) that is widely used by web developers to build fully functional websites quickly and efficiently. The platform is designed using the .NET framework, and it offers a wide range of features, including drag-and-drop site building capabilities and support for multiple websites.

The CMS is an excellent solution for businesses looking to develop their online presence without getting bogged down in the technical details. However, despite its many benefits, DNN is not immune to security vulnerabilities. One such vulnerability is CVE-2017-9822.

CVE-2017-9822 is a critical security flaw that was detected in versions of DNN prior to 9.1.1. The vulnerability enables attackers to execute code remotely using a cookie, which is a small text file used to store user data on a website.

When exploited, this vulnerability can allow hackers to gain full control of a website, including accessing sensitive information like customer data, credit card details, and even install malicious software on the server. This can result in significant financial losses, reputational damage, and legal ramifications for businesses that rely on DNN.

In conclusion, DNN is an excellent CMS solution for businesses looking to develop their online presence. However, like many software products, it is not immune to security vulnerabilities. CVE-2017-9822 is a critical security flaw that can have severe consequences when exploited. To protect your website, it is essential to take the necessary precautions and regularly scan for vulnerabilities using a trusted security platform like s4e.io. With its pro features, users can easily and quickly learn about vulnerabilities in their digital assets, making it an essential tool for businesses of all sizes.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to take the following precautions:

  • Update your DNN installation to version 9.1.1 or later.
  • Use strong passwords and two-factor authentication to secure your DNN account.
  • Use firewalls and intrusion detection systems to monitor traffic to and from your website.
  • Regularly scan your website for vulnerabilities using a trusted security platform.
  • Implement a disaster recovery plan that includes regular data backups and testing.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.