→ كل المشاريع

CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload

بواسطة @h4x0r-dz

نشِط 14

POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

عن هذا المشروع

CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite I'm a simple man, I see cvss:10/10 I go in xD I saw this new CVE CVE-2025-64095 DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite The default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. > Description An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. https://nvd.nist.gov/vuln/detail/CVE-2025-64095 Base Score: 10.0 CRITICAL 🤷‍♂️ It turns out not that critical after all, since you can not upload a web shell like ASP, ASPX..etc (in the default configuration at least ) you can upload images + SVG only . you can only upload/write existing files in the web server + in a specific path, you can not even upload a file in the root dir . Patch Diffing Analysis: DNN Platform 10.1.0 10.1.1 Since all versions before 10.1.1 are vulnerable, i took the DNN Platform 10.1.0 (the last vulnerable version ) Introduction

من ملف README الخاص بالمشروع على GitHub

النجوم
14
التفريعات
4
آخر تحديث
31/10/2025

أضف هذه الشارة إلى ملف README

أظهر أن مشروعك مُدرج على «صُنع في الجزائر».

Made in Algeria
[![Made in Algeria](https://www.madeinalgeria.dev/badge/cve-2025-64095-dnn-unauthenticated-arbitrary-file-upload.svg)](https://www.madeinalgeria.dev/projects/cve-2025-64095-dnn-unauthenticated-arbitrary-file-upload)

مشاريع ذات صلة