Critical severity9.8NVD Advisory· Published Jan 21, 2020· Updated Jun 17, 2026
CVE-2019-19392
CVE-2019-19392
Description
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:fordnn:usersexportimport:*:*:*:*:*:dotnetnuke:*:*+ 1 more
- cpe:2.3:a:fordnn:usersexportimport:*:*:*:*:*:dotnetnuke:*:*range: <1.2.0
- (no CPE)range: <1.2.0
- DNN/UsersExportImport moduledescription
Patches
Vulnerability mechanics
References
2- blog.joaoorvalho.com/description-cve-2019-19392/nvdExploitThird Party Advisory
- github.com/fordnn/usersexportimport/commits/masternvdThird Party Advisory
News mentions
0No linked articles in our index yet.