DNN (DotNetNuke) versions 9.2 through 9.2.2 use a weak encryption algorithm to protect input parameters because of an incomplete fix for CVE-2018-15811. This cryptographic weakness enables attackers to craft malicious DNNPersonalization cookies that can be deserialized, leading to remote code execution.
id: CVE-2018-18325
info:
name: DotNetNuke 9.2 - 9.2.2 - Weak Encryption & Cookie Deserialization
...