Dotnetnuke < 10.3.3 User registration approval authorization bypass (GHSA-fpr5-67pq-3hf5)

high Nessus Plugin ID 339646

Synopsis

An ASP.NET application running on the remote web server is affected by a vulnerability.

Description

According to its self-reported version, the instance of Dotnetnuke running on the remote web server is prior to 10.3.3.
It is, therefore, affected by a vulnerability.

- An authorization vulnerability could allow an authenticated user to approve pending user registrations without administrative privileges. Sites using administrator approval for new user registrations should upgrade immediately to ensure registration approval actions are properly restricted. A vulnerability was identified in the platform's user registration approval process where authorization checks were not consistently enforced before approving pending user accounts. Under certain conditions, an authenticated user with minimal privileges could perform registration approval actions that should be restricted to authorized administrators. Successful exploitation could bypass administrative review of new user registrations, allowing pending accounts to become active without the intended approval process. This undermines the integrity of moderated registration workflows and may allow unauthorized or self-approved accounts to gain access to the site. The impact is particularly significant for sites that rely on administrator approval as a security control, such as private communities, intranets, customer portals, or regulated environments where account approval is used to verify identity, eligibility, or organizational affiliation before granting access. In these environments, successful exploitation could allow unauthorized users to obtain access to protected content or functionality that would otherwise require administrative approval. (GHSA-fpr5-67pq-3hf5)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Dotnetnuke version 10.3.3 or later.

See Also

http://www.nessus.org/u?7142c4a8

Plugin Details

Severity: High

ID: 339646

File Name: dotnetnuke_GHSA-fpr5-67pq-3hf5.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 8/26/2026

Updated: 8/26/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:dnnsoftware:dotnetnuke, cpe:/a:dotnetnuke:dotnetnuke

Required KB Items: installed_sw/DNN

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2026

Vulnerability Publication Date: 8/25/2026

Reference Information

CWE: 639