Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2017-14523

Disclosure Date: January 26, 2018 (last updated November 08, 2023)
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack
0
Attacker Value
Unknown

CVE-2017-14522

Disclosure Date: January 26, 2018 (last updated November 08, 2023)
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website
0
Attacker Value
Unknown

CVE-2017-14521

Disclosure Date: January 26, 2018 (last updated November 26, 2024)
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
0