Server-Side Request Forgery (SSRF) in DotNetNuke - #VU146093
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause the server to initiate requests to arbitrary network resources.
The vulnerability exists due to server-side request forgery (ssrf) in the Journal module link preview functionality when processing user-supplied URLs. A remote user can supply a crafted URL to cause the server to initiate requests to arbitrary network resources.
Depending on the deployment environment, exploitation may allow access to network resources that are not directly reachable from the Internet.