Skip to main content
Vulnerability Database/CVE-2025-64094

CVE-2025-64094: DNN CMS SVG File Upload XSS Vulnerability

CVE-2025-64094 is a cross-site scripting vulnerability in DNN CMS that affects SVG file upload sanitization, allowing attackers to execute malicious scripts. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2025-64094 Overview

CVE-2025-64094 is a stored cross-site scripting (XSS) vulnerability in DNN Platform, formerly known as DotNetNuke. DNN is an open-source web content management system built on the Microsoft .NET stack. The flaw resides in the sanitization logic applied to uploaded Scalable Vector Graphics (SVG) files. Prior to version 10.1.1, the sanitizer did not cover all possible XSS payload scenarios embedded in SVG markup. The issue represents an incomplete fix for the earlier CVE-2025-48378 vulnerability. An authenticated user with upload privileges can craft an SVG containing script content that executes in the browser of anyone who views the file.

Critical Impact

Authenticated attackers can upload malicious SVG files that execute JavaScript in victim browsers, potentially leading to session theft, credential harvesting, or administrative account takeover.

Affected Products

  • DNN Platform (DotNetNuke) versions prior to 10.1.1
  • DNN-based content management deployments accepting SVG uploads
  • Sites relying on the incomplete CVE-2025-48378 patch

Discovery Timeline

  • 2025-10-28 - CVE-2025-64094 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-64094

Vulnerability Analysis

The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. It stems from incomplete input sanitization on uploaded SVG documents. SVG is an XML-based image format that natively supports embedded JavaScript through <script> elements, event handler attributes such as onload and onclick, and <foreignObject> content. DNN's sanitizer filters known dangerous constructs but did not enumerate every vector an attacker can use to smuggle executable script into an SVG. When another user retrieves the file through a browser that renders SVG inline, the malicious payload executes in the context of the DNN site origin.

Root Cause

The root cause is an incomplete deny-list sanitization routine introduced as a fix for CVE-2025-48378. The prior patch addressed specific XSS vectors but missed alternative SVG constructs that also execute script. Attackers can bypass the filter using less common event handlers, namespaced elements, or CDATA-wrapped script content. Because SVG files are served with an image-related MIME type but interpreted as active content by browsers, the sanitizer must exhaustively strip all executable constructs rather than target known payloads.

Attack Vector

Exploitation requires an authenticated account with permission to upload files to a DNN site. The attacker crafts an SVG containing embedded JavaScript that survives the sanitizer. The file is uploaded through the standard file management or module upload interface. When a victim, typically a site administrator or another authenticated user, opens or previews the SVG, the browser executes the embedded script under the DNN site origin. User interaction is required, which limits scope but does not prevent exploitation in shared workspaces. Technical details are available in the GitHub Security Advisory GHSA-hmvq-8p83-cq52.

Detection Methods for CVE-2025-64094

Indicators of Compromise

  • SVG files uploaded to the DNN Portals directory containing <script>, onload, onerror, or <foreignObject> elements
  • HTTP requests to /DesktopModules/ or /Portals/ paths returning SVG content with embedded scripts
  • Unexpected outbound requests from administrator browsers immediately after opening an SVG asset
  • New privileged user accounts or role changes following administrator SVG viewing activity

Detection Strategies

  • Scan the DNN Portals and Content directories for SVG files containing script tags or event handler attributes
  • Review web server logs for uploads of .svg files from non-standard user accounts
  • Inspect the DNN event log for file upload actions correlated with subsequent administrative changes
  • Deploy content inspection at the web application firewall to flag SVG payloads containing JavaScript

Monitoring Recommendations

  • Monitor authenticated file upload endpoints for SVG submissions and validate their content
  • Alert on session or credential activity originating from browsers that recently rendered user-uploaded SVG files
  • Track DNN version metadata across deployed sites to identify instances still running versions below 10.1.1
  • Correlate file access telemetry with browser process behavior to identify script execution from static assets

How to Mitigate CVE-2025-64094

Immediate Actions Required

  • Upgrade DNN Platform to version 10.1.1 or later on all affected sites
  • Audit existing SVG files in Portals directories and remove any containing script content or event handlers
  • Restrict SVG upload permissions to trusted roles until the patch is deployed
  • Rotate administrative credentials and session tokens if suspicious SVG uploads are identified

Patch Information

The vulnerability is fixed in DNN Platform version 10.1.1. The fix expands SVG sanitization coverage to address the vectors missed by the CVE-2025-48378 patch. Refer to the DNN Platform security advisory GHSA-hmvq-8p83-cq52 for release details and upgrade instructions.

Workarounds

  • Disable SVG uploads by removing svg from the allowed file extensions list in DNN Host Settings
  • Serve user-uploaded SVG files with a Content-Disposition: attachment header to prevent inline browser rendering
  • Apply a strict Content Security Policy that blocks inline script execution on portal pages
  • Limit file upload roles to administrators while planning the upgrade to 10.1.1
bash
# Configuration example: remove SVG from allowed extensions in DNN Host Settings
# Host > Host Settings > Other Settings > Allowable File Extensions
# Before: jpg,jpeg,jpe,gif,bmp,png,svg,doc,docx,xls,xlsx,ppt,pptx,pdf,txt,xml,xsl,xsd,css,zip,rar
# After:  jpg,jpeg,jpe,gif,bmp,png,doc,docx,xls,xlsx,ppt,pptx,pdf,txt,xml,xsl,xsd,css,zip,rar

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.