一个关键的 DotNetNuke 漏洞允许攻击者上传恶意 SVG 文件,执行跨站脚本(XSS),并通过已认证用户操作获取服务器控制权。
techradar.com
'Chaining vulnerabilities is the hallmark of a sophisticated attack': 750,000 websites must be patched as Microsoft's popular open source Dotnetnuke CMS hit by an XSS flaw that allows attackers to hijack admin sessions and take over entire web servers
Create attached notes ...
