<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[New research from Matei &quot;Mal&quot; Bădănoiu (Pentest-Tools.com):]]></title><description><![CDATA[<p>New research from Matei "Mal" Bădănoiu (Pentest-Tools.com):</p><p>Stored XSS to RCE in DNN Platform (DotNetNuke), CVE-2026-40321.</p><p>SVG upload with javascript: in an &lt;a href&gt; bypasses the filter. The /API/personaBar/ConfigConsole/UpdateConfigFile endpoint writes an ASPX backdoor to the web root. whoami → iis apppool, Potato your way to SYSTEM.</p><p>Delivery: DNN's own internal messaging. No external infra.</p><p><a href="https://pentest-tools.com/blog/dotnetnuke-xss-to-rce" rel="nofollow noopener"><span>https://</span><span>pentest-tools.com/blog/dotnetn</span><span>uke-xss-to-rce</span></a></p><p><a href="https://infosec.exchange/tags/RedTeam" rel="tag">#<span>RedTeam</span></a> <a href="https://infosec.exchange/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/CVE" rel="tag">#<span>CVE</span></a> <a href="https://infosec.exchange/tags/AppSec" rel="tag">#<span>AppSec</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/442/898/889/348/299/original/f641e7ca2c89417e.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/da47e2ef-7f4f-497a-8188-69902d28f55b/new-research-from-matei-mal-bădănoiu-pentest-tools.com</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:34:58 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/da47e2ef-7f4f-497a-8188-69902d28f55b.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Apr 2026 13:20:41 GMT</pubDate><ttl>60</ttl></channel></rss>