EXPOSURES › CVE-2018-18325
CVE-2018-18325
HIGH ⌖ ON CISA KEV · EXPLOITEDDotNetNuke used weak encryption to protect input parameters, an incomplete patch for CVE-2018-15811 that was actively exploited in the wild.
DotNetNuke (DNN) contained an inadequate encryption strength vulnerability due to the use of a weak encryption algorithm to protect input parameters. This CVE resolves an incomplete patch for CVE-2018-15811 and was actively exploited in the wild. DIB orgs should care because weak encryption can lead to data breaches and compliance failures, and the incomplete patch shows negligence in addressing known vulnerabilities.
Shame score — The vendor used weak encryption and failed to properly patch a known vulnerability, leading to active exploitation in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.