CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload
بواسطة @h4x0r-dz
نشِط 14
POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
عن هذا المشروع
CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite I'm a simple man, I see cvss:10/10 I go in xD I saw this new CVE CVE-2025-64095 DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite The default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. > Description An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. https://nvd.nist.gov/vuln/detail/CVE-2025-64095 Base Score: 10.0 CRITICAL 🤷♂️ It turns out not that critical after all, since you can not upload a web shell like ASP, ASPX..etc (in the default configuration at least ) you can upload images + SVG only . you can only upload/write existing files in the web server + in a specific path, you can not even upload a file in the root dir . Patch Diffing Analysis: DNN Platform 10.1.0 10.1.1 Since all versions before 10.1.1 are vulnerable, i took the DNN Platform 10.1.0 (the last vulnerable version ) Introduction
من ملف README الخاص بالمشروع على GitHub
- النجوم
- 14
- التفريعات
- 4
- آخر تحديث
- 31/10/2025
أضف هذه الشارة إلى ملف README
أظهر أن مشروعك مُدرج على «صُنع في الجزائر».
[](https://www.madeinalgeria.dev/projects/cve-2025-64095-dnn-unauthenticated-arbitrary-file-upload)