New research from our team: stored XSS to RCE in DNN Platform (formerly DotNetNuke), CVE-2026-40321. SVG upload. javascript: URI inside an <a href>. Filter waves it through. Authenticated endpoint writes an ASPX backdoor to the web root. whoami returns iis apppool, Potato to SYSTEM.
0 likes 1 replies
?