Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
forDNN.UsersExportImport 安全漏洞
Vulnerability Description
forDNN.UsersExportImport module 1.2.0之前版本(用于DNN)中存在安全漏洞。攻击者可通过导入XML/CSV文件利用该漏洞创建管理员账户,进而访问管理面板。
CVSS Information
N/A
Vulnerability Type
N/A