DNN (DotNetNuke) versions 9.2 through 9.2.1 use a weak encryption algorithm to protect input parameters. This cryptographic weakness enables attackers to craft malicious DNNPersonalization cookies that can be deserialized, leading to remote code execution.
id: CVE-2018-15811
info:
name: DotNetNuke 9.2 - 9.2.1 - Weak Encryption & Cookie Deserialization
...