Hackers exploit simple SVG uploads in Dot Net Nuke to quietly take over servers, turning harmless images into powerful backdoor delivery tools | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
'Chaining vulnerabilities is the hallmark of a sophisticated attack': 750,000 websites must be patched as Microsoft's popular open source Dotnetnuke CMS hit by an XSS flaw that allows attackers to hijack admin sessions and take over entire web servers
Hidden XSS flaw in Dot Net Nuke turns trusted uploads into attack vectors
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Malicious SVG uploads in Dot Net Nuke execute Java Script when clicked
Attack requires only one admin click to trigger full server compromise
XSS flaw allows attackers to act using the victim’s authenticated session
Cybercriminals can now chain exploits together and gain control of web servers by exploiting a critical cross-site scripting (XSS) vulnerability in the Dot Net Nuke CMS.
The flaw, tracked as CVE-2026-40321, affects the popular open-source platform built on Microsoft technology and powers over 750,000 websites globally.
According to Pentest Tools, a malicious SVG file containing Java Script code can be uploaded as an image, and clicking on this file executes the embedded payload and writes a backdoor file directly onto the server.
Around 500,000 Word Press websites could be at risk from crucial plugin security flaw
60,000 Word Press sites at risk due to plugin security flaw
Nearly a million Word Press websites could be at risk from this serious plugin security flaw
How attackers bypass the CMS filters to upload malicious files
By default, Dot Net Nuke allows users to register accounts and upload SVG files to their own user directories.
Even if these SVG files contain Java Script inside an anchor tag, the platform’s content filter does not prevent the upload, and if a victim clicks on an SVG file that contains simple payloads, it is enough to trigger XSS.
Once a victim clicks the booby-trapped image, the Java Script payload executes in the browser using the existing authenticated session.
The attackers then exploit /API/persona Bar/Config Console/Update Config File, an authenticated endpoint that allows users with sufficient privileges to write files to the server.
The payload generates a new ASPX web shell, essentially a backdoor that accepts commands via URL parameters.
With this, the attacker runs malware, steals data, or disables security tools on the underlying Windows server.
Critical n 8n flaws discovered - here's how to stay safe
Huge numbers of web stores are facing attack from this dangerous new malware
Now that's different - hackers use miniature SVG images to try and hide credit card stealer
This vulnerability is dangerous because the attack chain completely defeats regular security defenses.
All the attacker needs is to convince a single privileged user to click on a malicious image, which can compromise the entire system — no password needed, and there is no need to exploit server software.
Regular antivirus software will be of little or no help here because it may not detect the attack.
The malicious payload is delivered via a legit SVG file and executed with native browser features, so the tool becomes irrelevant.
A configured firewall would also not block the outbound connection because the attack uses standard HTTP traffic.
Malware removal tools are ineffective against a backdoor that was never installed through traditional means but was instead written to disk by an authenticated request.
The vulnerability is serious, but thankfully, the attack only works when several conditions align perfectly.
The attacker needs a registered account on the target site, the ability to upload SVG files, and a privileged user who clicks on a suspicious attachment.
Administrators, therefore, must be vigilant, check file extensions, and disable unnecessary user uploads for protection.
Although there is an official patch for the vulnerability, which organizations running Dot Net Nuke should prioritize, administrators should also review user registration policies.
If anonymous file uploads are not necessary, then they should be disabled immediately.
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a Ph D in sciences, which provided him with a solid foundation in analytical thinking.
You must confirm your public display name before commenting
1'The storm is here': Why you and your neighbors may be paying multibillion-dollar bill for AI data centers right now — but that may not last long as more US states join revolt against unjust 'socialist' approach to electricity bills
2 Space X's theorized data centers in space face 'significant technical complexity and unproven technologies,' and the 'unpredictable environment of space' means they may not be commercially viable
3 Smart-home brand Dreame showed me a rocket-powered electric car, and then things got weirder from there
4'The ocean is really unlimited in terms of how much energy is available': No land, no fuel, no cables — how wave-powered ocean platforms could tackle the power needs of AI data centers
5I tried Google’s new AI wardrobe feature with Motorola’s Razr — and it turns your photos into a surprisingly useful digital closet full of outfits
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



