CVE-2017-0929 describes a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class of DNN (DotNetNuke) versions prior to 9.2.0. This high-severity flaw (CVSS 7.5) allows unauthenticated attackers to access internal network resources, posing a significant risk of information disclosure. While not currently listed on CISA's KEV catalog, its high EPSS score and available Nuclei templates indicate a strong likelihood of exploitation, despite a lack of public exploit code or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.0CPE matchmatch criteria | cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.