Listen to this Post
How the mentioned CVE works:
This CVE is a bypass of a previous patch (CVE-2025-48378) for SVG uploads in DNN. The platform performs sanitization on uploaded SVG files to remove malicious scripts. However, the validation checks for script elements are not comprehensive. An attacker can craft a malicious SVG file containing embedded JavaScript that evades the existing filters. When this SVG is uploaded and subsequently viewed by a user, the malicious script executes within the victim’s browser session. This allows the attacker to perform actions on behalf of the user, such as stealing session cookies, performing unauthorized state-changing requests, or defacing the web page.
Platform: DNN
Version: < 10.3.0
Vulnerability: Stored XSS
Severity: Moderate
date: 2025-10-28
Prediction: 2025-11-11
What Undercode Say:
curl -F '[email protected]' http://dnnsite.com/API/Upload`
<h2 style="color: blue;"></h2>
<h2 style="color: blue;">
