CVE-2017-0929: Dnnsoftware DotNetNuke

High severity, CVSS 7.5. EPSS: 12.5% chance of exploitation in the next 30 days.

DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

Affected products

Published 2018-07-03. Last modified 2026-06-17.