PatchSiren cyber security CVE debrief
CVE-2015-2794 Dnnsoftware CVE debrief
CVE-2015-2794 is a critical DotNetNuke (DNN) vulnerability affecting versions before 7.4.1. A remote attacker can send a direct request to the installation wizard and potentially force a reinstall of the application, which can result in SuperUser-level access.
- Vendor
- Dnnsoftware
- Product
- Dotnetnuke
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-06
- Advisory updated
- 2026-05-13
Who should care
DNN administrators, hosting providers, and security teams responsible for internet-facing DotNetNuke installations, especially any system running a version earlier than 7.4.1.
Technical summary
NVD describes the issue as an unauthenticated network attack against Install/InstallWizard.aspx in DotNetNuke before 7.4.1. The result can be application reinstallation and SuperUser access. NVD rates the issue CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and the vulnerable version range extends through 07.04.00.
Defensive priority
Immediate. This is a remotely exploitable, no-authentication, high-impact flaw with full confidentiality, integrity, and availability consequences in NVD scoring.
Recommended defensive actions
- Upgrade DotNetNuke to 7.4.1 or later.
- If immediate upgrade is not possible, follow the vendor workaround and security guidance referenced by DNN.
- Restrict access to the installer endpoint and verify it is not reachable from untrusted networks.
- Review logs and configuration for any unexpected reinstall activity, SuperUser creation, or other unauthorized changes.
- Treat affected systems as potentially compromised until integrity is confirmed and privileged accounts are reviewed.
Evidence notes
This debrief is based on the supplied NVD record and its cited references. The CVE description states that DotNetNuke (DNN) before 7.4.1 can be reinstalled through a direct request to Install/InstallWizard.aspx, enabling SuperUser access. NVD metadata lists the vulnerable CPE range through version 07.04.00, CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and CWE-264. References include a DNN workaround post, DNN security center patch guidance, DNN release notes, and a third-party exploit-db entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-2794 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-2794
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-2794 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-2794
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://dotnetnuke.codeplex.com/releases/view/615317
[email protected] - Release Notes, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/39777/
[email protected] - Exploit, Third Party Advisory, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.