PT-2024-21946 · Wondercms · Wondercms

Zer0Yu

·

Published

2024-03-05

·

Updated

2025-01-21

·

CVE-2024-27561

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WonderCMS version 3.1.3
Description A Server-Side Request Forgery (SSRF) issue in the installUpdateThemePluginAction function allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.
Recommendations For WonderCMS version 3.1.3, as a temporary workaround, consider disabling the installUpdateThemePluginAction function until a patch is available. Restrict access to the installThemePlugin parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-27561

Affected Products

Wondercms