Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Hackers exploit simple SVG uploads in DotNetNuke to quietly take over servers, turning harmless images into powerful backdoor delivery tools | TechRadar

Hidden XSS flaw in DotNetNuke turns trusted uploads into attack vectors Discover insights about hackers exploit simple svg uploads in dotnetnuke to quietly take

TechnologyInnovationBest PracticesGuideTutorial
Hackers exploit simple SVG uploads in DotNetNuke to quietly take over servers, turning harmless images into powerful backdoor delivery tools | TechRadar
Listen to Article
0:00
0:00
0:00

Hackers exploit simple SVG uploads in Dot Net Nuke to quietly take over servers, turning harmless images into powerful backdoor delivery tools | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

'Chaining vulnerabilities is the hallmark of a sophisticated attack': 750,000 websites must be patched as Microsoft's popular open source Dotnetnuke CMS hit by an XSS flaw that allows attackers to hijack admin sessions and take over entire web servers

Hidden XSS flaw in Dot Net Nuke turns trusted uploads into attack vectors

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Malicious SVG uploads in Dot Net Nuke execute Java Script when clicked

Attack requires only one admin click to trigger full server compromise

XSS flaw allows attackers to act using the victim’s authenticated session

Cybercriminals can now chain exploits together and gain control of web servers by exploiting a critical cross-site scripting (XSS) vulnerability in the Dot Net Nuke CMS.

The flaw, tracked as CVE-2026-40321, affects the popular open-source platform built on Microsoft technology and powers over 750,000 websites globally.

According to Pentest Tools, a malicious SVG file containing Java Script code can be uploaded as an image, and clicking on this file executes the embedded payload and writes a backdoor file directly onto the server.

Around 500,000 Word Press websites could be at risk from crucial plugin security flaw

60,000 Word Press sites at risk due to plugin security flaw

Nearly a million Word Press websites could be at risk from this serious plugin security flaw

How attackers bypass the CMS filters to upload malicious files

By default, Dot Net Nuke allows users to register accounts and upload SVG files to their own user directories.

Even if these SVG files contain Java Script inside an anchor tag, the platform’s content filter does not prevent the upload, and if a victim clicks on an SVG file that contains simple payloads, it is enough to trigger XSS.

Once a victim clicks the booby-trapped image, the Java Script payload executes in the browser using the existing authenticated session.

The attackers then exploit /API/persona Bar/Config Console/Update Config File, an authenticated endpoint that allows users with sufficient privileges to write files to the server.

The payload generates a new ASPX web shell, essentially a backdoor that accepts commands via URL parameters.

With this, the attacker runs malware, steals data, or disables security tools on the underlying Windows server.

Critical n 8n flaws discovered - here's how to stay safe

Huge numbers of web stores are facing attack from this dangerous new malware

Now that's different - hackers use miniature SVG images to try and hide credit card stealer

This vulnerability is dangerous because the attack chain completely defeats regular security defenses.

All the attacker needs is to convince a single privileged user to click on a malicious image, which can compromise the entire system — no password needed, and there is no need to exploit server software.

Regular antivirus software will be of little or no help here because it may not detect the attack.

The malicious payload is delivered via a legit SVG file and executed with native browser features, so the tool becomes irrelevant.

A configured firewall would also not block the outbound connection because the attack uses standard HTTP traffic.

Malware removal tools are ineffective against a backdoor that was never installed through traditional means but was instead written to disk by an authenticated request.

The vulnerability is serious, but thankfully, the attack only works when several conditions align perfectly.

The attacker needs a registered account on the target site, the ability to upload SVG files, and a privileged user who clicks on a suspicious attachment.

Administrators, therefore, must be vigilant, check file extensions, and disable unnecessary user uploads for protection.

Although there is an official patch for the vulnerability, which organizations running Dot Net Nuke should prioritize, administrators should also review user registration policies.

If anonymous file uploads are not necessary, then they should be disabled immediately.

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a Ph D in sciences, which provided him with a solid foundation in analytical thinking.

You must confirm your public display name before commenting

1'The storm is here': Why you and your neighbors may be paying multibillion-dollar bill for AI data centers right now — but that may not last long as more US states join revolt against unjust 'socialist' approach to electricity bills

2 Space X's theorized data centers in space face 'significant technical complexity and unproven technologies,' and the 'unpredictable environment of space' means they may not be commercially viable

3 Smart-home brand Dreame showed me a rocket-powered electric car, and then things got weirder from there

4'The ocean is really unlimited in terms of how much energy is available': No land, no fuel, no cables — how wave-powered ocean platforms could tackle the power needs of AI data centers

5I tried Google’s new AI wardrobe feature with Motorola’s Razr — and it turns your photos into a surprisingly useful digital closet full of outfits

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.