CVE-2017-9822

8.8HIGH

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

Published: 7/20/2017Updated: 10/22/2025

CISA Known Exploited Vulnerability

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

Required Action:

Apply updates per vendor instructions.

Due Date:

2022-05-03

Known Ransomware Use

Description

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

AI AnalysisPowered by AI

Affected Products

dnnsoftwaredotnetnuke

Available Exploits (1)

References