CyberSec.Space Logo
Back to CVE Browser

CVE-2019-19392

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1240%
EPSS Percentile31.37th
PublishedJan 21, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.

Affected Platforms (CPE)

πŸ“¦
Fordnn

Usersexportimport

< 1.2.0

References & Advisories

Related Vulnerabilities