Wondercms · Wondercms · CVE-2020-35313
Name of the Vulnerable Software and Affected Versions:
WonderCMS version 3.1.3
Description:
A server-side request forgery (SSRF) vulnerability in the `addCustomThemePluginRepository` function in `index.php` allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer. This issue affects authenticated users.
Recommendations:
For WonderCMS version 3.1.3, as a temporary workaround, consider disabling the `addCustomThemePluginRepository` function in `index.php` until a patch is available. Restrict access to the theme/plugin installer to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.