CVE-2026-40305
EUVD-2026-2355317.04.2026, 22:16
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dnnsoftware | dotnetnuke | 6.0.0 ≤ 𝑥 < 10.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration