Missing Authorization in DotNetNuke - #VU146089
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to interact with private journal posts without authorization.
The vulnerability exists due to missing authorization in the Journal module when recording likes on private journal posts. A remote user can add a like to a private journal entry they are not authorized to access to interact with private journal posts without authorization.
The issue does not expose the contents of private journal posts or allow modification of their content, but it may create visible interactions associated with private activity.