PT-2024-29352 · Wondercms · Wondercms
Junnair Manla
+3
·
Published
2024-07-30
·
Updated
2024-08-08
·
CVE-2024-41305
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WonderCMS version 3.4.3
Description
A Server-Side Request Forgery (SSRF) issue in the Plugins Page allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the
pluginThemeUrl parameter.Recommendations
For WonderCMS version 3.4.3, as a temporary workaround, consider restricting access to the Plugins Page or validating the
pluginThemeUrl parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SSRF
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wondercms