Server-Side Request Forgery (SSRF) in DotNetNuke - #VU146093

 

Server-Side Request Forgery (SSRF) in DotNetNuke - #VU146093

Published: August 28, 2026


Vulnerability identifier: #VU146093
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause the server to initiate requests to arbitrary network resources.

The vulnerability exists due to server-side request forgery (ssrf) in the Journal module link preview functionality when processing user-supplied URLs. A remote user can supply a crafted URL to cause the server to initiate requests to arbitrary network resources.

Depending on the deployment environment, exploitation may allow access to network resources that are not directly reachable from the Internet.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins