Dotnetnuke < 10.3.3 Content approval workflow bypass (GHSA-56m6-r25g-78x6)

high Nessus Plugin ID 339498

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- A vulnerability in the content workflow could allow a user with content editing permissions to publish their own changes without the required approval process. Sites using content approval workflows should upgrade to a patched release to ensure workflow approval requirements are consistently enforced. A vulnerability was identified in the platform's content workflow where workflow authorization was not consistently enforced during state transitions. Under certain conditions, a user with permission to create or edit content could bypass the configured approval process and publish their own changes without review by an authorized approver. Successful exploitation could undermine the integrity of content approval workflows by allowing unreviewed content to be published, defeating organizational controls designed to ensure editorial oversight, compliance, or change management before content becomes publicly visible.
(GHSA-56m6-r25g-78x6)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?8b95e37f

Plugin Details

Severity: High

ID: 339498

File Name: dotnetnuke_GHSA-56m6-r25g-78x6.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/25/2026

Updated: 8/25/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 863