UpendoVentures / Page-Settings-Editor

This is an editor that allows you to create, edit, and delete custom settings for pages in DNN CMS.
https://upendoventures.com/What/CMS/DNN
MIT License
4 stars 1 forks source link

CVE-2020-5188 (Medium) detected in dotnetnuke.core.9.9.0.nupkg #54

Open mend-bolt-for-github[bot] opened 1 year ago

mend-bolt-for-github[bot] commented 1 year ago

CVE-2020-5188 - Medium Severity Vulnerability

Vulnerable Library - dotnetnuke.core.9.9.0.nupkg

Provides basic references to the DotNetNuke.dll to develop extensions for the DNN Platform. For MVC or WebAPI please see other packages available as well

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.9.0.nupkg

Path to dependency file: /Modules/PageSettingsEditor/Upendo.Modules.PageSettingsEditor.csproj

Path to vulnerable library: /tmp/ws-ua_20230717013228_GHGMMD/dotnet_DIMSSU/20230717013228/DotNetNuke.Core.9.9.0/DotNetNuke.Core.9.9.0.nupkg,/tmp/ws-ua_20230717013228_GHGMMD/dotnet_DIMSSU/20230717013228/dotnetnuke.core/9.9.0/dotnetnuke.core.9.9.0.nupkg

Dependency Hierarchy: - :x: **dotnetnuke.core.9.9.0.nupkg** (Vulnerable Library)

Found in base branch: main

Vulnerability Details

DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

Publish Date: 2020-02-24

URL: CVE-2020-5188

CVSS 3 Score Details (6.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None

For more information on CVSS3 Scores, click here.


Step up your Open Source Security Game with Mend here