Pentest-Tools.com @pentest-tools.com · Apr 21

New research from our team: stored XSS to RCE in DNN Platform (formerly DotNetNuke), CVE-2026-40321. SVG upload. javascript: URI inside an <a href>. Filter waves it through. Authenticated endpoint writes an ASPX backdoor to the web root. whoami returns iis apppool, Potato to SYSTEM.

0 likes 1 replies

?

Replies

Pentest-Tools.com · Apr 21

The part worth stealing is the delivery. Instead of external phishing infrastructure, Matei (Mal) sent the SVG to a SuperUser through DNN's own internal messaging. No external domain. Just a message inside the app the victim already trusts. pentest-tools.com/blog/dotnetn... #RedTeam