Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-104226. PoCs published by Semen Alexandrovich Lyhin.
AI-analyzed exploit summary This JavaScript exploit demonstrates an unauthenticated stored XSS vulnerability in DNN v9.3.2, where a malicious user registration with a crafted 'Display Name' triggers an admin notification. When the admin clicks the notification, the XSS payload executes, granting the attacker admin privileges via API calls.
Description
DotNetNuke 9.3.2 - Cross-Site Scripting
Exploits (1)
This JavaScript exploit demonstrates an unauthenticated stored XSS vulnerability in DNN v9.3.2, where a malicious user registration with a crafted 'Display Name' triggers an admin notification. When the admin clicks the notification, the XSS payload executes, granting the attacker admin privileges via API calls.