CVE-2017-0929: Dnnsoftware DotNetNuke
High severity, CVSS 7.5. EPSS: 12.5% chance of exploitation in the next 30 days.
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
Affected products
- Dnnsoftware DotNetNuke: before 9.2.0 (fixed in 9.2.0)
Published 2018-07-03. Last modified 2026-06-17.