Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-27563
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
0
Attacker Value
Unknown
CVE-2024-27561
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.
0
Attacker Value
Unknown
CVE-2020-35313
Disclosure Date: April 20, 2021 (last updated February 22, 2025)
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
0
Attacker Value
Unknown
CVE-2020-35314
Disclosure Date: April 20, 2021 (last updated February 22, 2025)
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.
0
Attacker Value
Unknown
CVE-2020-29469
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacker to inject the XSS payload in the Setting - Menu and each time any user will visits the website directory, the XSS triggers and attacker can steal the cookie according to the crafted payload.
0
Attacker Value
Unknown
CVE-2020-29233
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.
0
Attacker Value
Unknown
CVE-2020-29247
Disclosure Date: December 24, 2020 (last updated February 22, 2025)
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.
0