Dotnetnuke < 10.3.3 Unauthorized comments on private journal posts (GHSA-86mr-4mmw-j9g2)

high Nessus Plugin ID 339513

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- An authorization vulnerability in the Journal module could allow an authenticated user to add comments to private journal posts they are not authorized to view. Sites using the Journal module should upgrade to a patched release to ensure comment operations respect journal privacy settings. A vulnerability was identified in the Journal module's handling of comments on private journal posts. Under certain conditions, insufficient authorization checks could allow an authenticated user with minimal privileges to add comments to private journal entries that they are not permitted to view or interact with. While the vulnerability does not expose the contents of private journal posts, it allows unauthorized users to add comments to private content. In addition to compromising the integrity of private activity streams, this could be used for social engineering by creating the false impression that the commenter had legitimate access to or participation in a private discussion. (GHSA-86mr-4mmw-j9g2)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?2d4700c9

Plugin Details

Severity: High

ID: 339513

File Name: dotnetnuke_GHSA-86mr-4mmw-j9g2.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/25/2026

Updated: 8/25/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 862