Dotnetnuke < 10.3.3 Authorization bypass in image processor (GHSA-g8w5-h3rm-g8rj)

high Nessus Plugin ID 339645

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- An authorization vulnerability in the Image Processor could allow an unauthenticated user to access image files that were intended to be protected by DNN's file and folder permissions. Sites using restricted or secure file storage should upgrade to a patched release to ensure image processing operations consistently enforce configured access controls. A vulnerability was identified in the Image Processor where authorization checks were not consistently enforced before processing protected image files. Under certain conditions, an unauthenticated user could retrieve images stored in locations intended to restrict anonymous access. Successful exploitation could disclose sensitive images that administrators expected to remain protected by DNN's file authorization model. Depending on how the platform is used, affected images could include user-uploaded media, scanned documents, screenshots, branding assets, or other confidential visual content. (GHSA-g8w5-h3rm-g8rj)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?80af2633

Plugin Details

Severity: High

ID: 339645

File Name: dotnetnuke_GHSA-g8w5-h3rm-g8rj.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/26/2026

Updated: 8/26/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 200, 284, 639, 862