DNN, Stored Cross-Site Scripting, CVE-2025-48378 (Moderate)

Listen to this Post

How the mentioned CVE works:

This CVE is a bypass of a previous patch (CVE-2025-48378) for SVG uploads in DNN. The platform performs sanitization on uploaded SVG files to remove malicious scripts. However, the validation checks for script elements are not comprehensive. An attacker can craft a malicious SVG file containing embedded JavaScript that evades the existing filters. When this SVG is uploaded and subsequently viewed by a user, the malicious script executes within the victim’s browser session. This allows the attacker to perform actions on behalf of the user, such as stealing session cookies, performing unauthorized state-changing requests, or defacing the web page.
Platform: DNN
Version: < 10.3.0
Vulnerability: Stored XSS
Severity: Moderate
date: 2025-10-28

Prediction: 2025-11-11

What Undercode Say:

curl -F '[email protected]' http://dnnsite.com/API/Upload`
<h2 style="color: blue;">
</h2>
<h2 style="color: blue;">
</h2>
<h2 style="color: blue;">
grep -r “svg” /DNN/Platform/Components/`

How Exploit:

Craft malicious SVG with script payload. Upload via authorized file upload feature. Victim views the uploaded image, triggering script execution.

Protection from this CVE:

Update to DNN 10.3.0. Implement strict Content Security Policy. Sanitize all user-supplied SVG content.

Impact:

Session hijacking. Data exfiltration. Website defacement. Privilege escalation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top