Published: Jun 27, 2011
Version: 1.0
Maximum Severity Rating: medium
Background
DotNetNuke support applying different permissions to modules and pages.
Issue Summary
If a user has edit permissions to a module, this incorrect grants them access to manage the module, allowing them to access all permissions and change them as desired.
Mitigating factors
User may have a valid account to login and must have edit permissions on a page or module.
Affected DotNetNuke versions
Non-Affected Versions:
Fix(s) for issue
To fix this problem, you are recommended to update to the latest version of DotNetNuke (5.6.3 at time of writing)
Acknowledgments
Laurence Neville
Security Policy
Click here to read more details on the DotNetnuke Security Policy