Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20877
HistoryJul 23, 2019 - 4:48 a.m.

Remote Code Execution (RCE)

2019-07-2304:48:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33

EPSS

0.973

Percentile

99.9%

DNN.Platform is vulnerable to remote code execution (RCE). This is due to the application storing profile information for users in the DNNPersonalization cookie as XML and the structure includes a type attribute that instructs the server the type of object to create upon deserialization. The deserialization vulnerability in the cookie allows a remote attacker to execute arbitrary code on the system by submitting a malicious cookie to the server.