Dotnetnuke < 10.3.3 Permission precedence flaw in module permissions (GHSA-hqgc-qj63-mx24)

high Nessus Plugin ID 339497

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- A permission evaluation flaw could allow users with page-level content permissions to access module management features despite explicit module-level restrictions. Sites relying on module-level permission overrides should upgrade to a patched release to ensure access restrictions are consistently enforced. A vulnerability was identified in the platform's permission evaluation logic where, under certain conditions, explicit module-level access restrictions were not consistently enforced when broader page- level permissions were present. This could allow users granted page-level content management permissions to access module administration features that an administrator had explicitly restricted at the module level. As a result, module-specific permission settings may not behave as expected, potentially allowing unauthorized administrative actions within affected modules. (GHSA-hqgc-qj63-mx24)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?65706cc3

Plugin Details

Severity: High

ID: 339497

File Name: dotnetnuke_GHSA-hqgc-qj63-mx24.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/25/2026

Updated: 8/25/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 863