New research from Matei "Mal" Bădănoiu (Pentest-Tools.com):
Uncategorized
1
Posts
1
Posters
1
Views
-
New research from Matei "Mal" Bădănoiu (Pentest-Tools.com):
Stored XSS to RCE in DNN Platform (DotNetNuke), CVE-2026-40321.
SVG upload with javascript: in an <a href> bypasses the filter. The /API/personaBar/ConfigConsole/UpdateConfigFile endpoint writes an ASPX backdoor to the web root. whoami → iis apppool, Potato your way to SYSTEM.
Delivery: DNN's own internal messaging. No external infra.
https://pentest-tools.com/blog/dotnetnuke-xss-to-rce
#RedTeam #InfoSec #CVE #AppSec

-
R relay@relay.infosec.exchange shared this topic