S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 15, 2025

CVE-2018-15811 Scanner

CVE-2018-15811 Scanner - Remote Code Execution (RCE) vulnerability in DotNetNuke

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-15811
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DotNetNuke, maintained by DNN Software, is a leading web content management system utilized by organizations for creating and maintaining websites. It serves businesses, educational institutions, and government agencies for crafting dynamic and functional websites with ease. DotNetNuke offers features like content management, design solutions, and SEO capabilities. The platform is built using .NET and provides extensibility through modules and skins, allowing users to customize their web presence. It is widely adopted due to its flexibility and robustness, supporting various web development needs.

The Remote Code Execution (RCE) vulnerability discovered in DotNetNuke versions 9.2 through 9.2.1 allows attackers to take control over the application. This critical flaw arises from the use of weak encryption algorithms, which leaves input parameters vulnerable to tampering. By crafting malicious cookies, attackers can trigger deserialization attacks that result in executing unauthorized code. The vulnerability thus poses a significant security risk to businesses using affected DotNetNuke versions, potentially compromising sensitive data and operations.

The vulnerability involves weak encryption that can be exploited by attackers through malformed DNNPersonalization cookies. When such cookies are crafted and deserialized, they lead to execution of arbitrary code on the server. The specific endpoint affected appears to be related to how the DotNetNuke application handles personalization settings. Attackers exploit the vulnerability by inserting malicious objects within cookies that invoke internal methods. Recognizing the vulnerable parameter and endpoint can help in understanding the attack vector used by threat actors.

If exploited, this vulnerability could lead to several critical issues including unauthorized access to system resources and execution of arbitrary code. Businesses can experience data breaches, leading to loss of sensitive information, and potentially damaging their reputation. Additionally, attackers could install backdoors, compromising the integrity and availability of the web applications powered by DotNetNuke. Customers relying on these applications might also face a risk of being part of further malicious activities conducted by hijacked servers.

REFERENCES

Solution Advice
  • Update DotNetNuke to version 9.2.2 or later to address the weak encryption issue.
  • Enhance encryption algorithms used within the application to be aligned with current cryptographic standards.
  • Regularly audit and monitor web applications for unauthorized cookie manipulations and deserialization attempts.
  • Implement security controls to detect and mitigate injection attempts promptly.
  • Consider network segmentation to limit potential lateral movement in case of exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-15811 Scanner - Remote Code Execution (RCE) vulnerability in DotNetNuke | S4E