Dotnetnuke < 10.3.3 Unauthorized file metadata disclosure in restricted folders (GHSA-74j7-h73j-qmc9)

high Nessus Plugin ID 339476

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- An authorization vulnerability could allow an authenticated user to retrieve file names and metadata from folders they are not authorized to browse. Sites using restricted folders should upgrade to a patched release to ensure folder access permissions are consistently enforced. A vulnerability was identified in the platform's file management functionality where authorization checks for retrieving file information were inconsistent with those used for folder browsing. Under certain conditions, an authenticated user with minimal privileges could obtain file names and related metadata from folders that were otherwise inaccessible to them. Although the vulnerability does not expose the contents of affected files, the disclosure of file names and metadata may reveal sensitive information about protected resources and could facilitate targeted follow-on attacks against those assets. (GHSA-74j7-h73j-qmc9)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?f8f47f7e

Plugin Details

Severity: High

ID: 339476

File Name: dotnetnuke_GHSA-74j7-h73j-qmc9.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/25/2026

Updated: 8/25/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 862