CVE-2017-9822General(dnnsoftware / dotnetnuke)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dotnetnuke

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
dotnetnuke

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-19: 1Technical Details · 2026-08-19: 108-19
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • FattestSack@FattestSack
    General

    @DanBilzerian Florida’s county election sites are built on VR Systems, and that stack has a documented critical-vulnerability history (one of the worst RCE track records in the CMS world; see CVE-2017-9822 & 2016 alleged GRU operation).

    Post summary

    The tweet references VR Systems’ known RCE history, specifically CVE‑2017‑9822, but offers no PoC, exploit code, patch guidance, or evidence of active exploitation.

    10140200
    654 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdnnsoftwaredotnetnuke---

Explore more