PT-2024-29352 · Wondercms · Wondercms

Junnair Manla

+3

·

Published

2024-07-30

·

Updated

2024-08-08

·

CVE-2024-41305

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WonderCMS version 3.4.3
Description A Server-Side Request Forgery (SSRF) issue in the Plugins Page allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
Recommendations For WonderCMS version 3.4.3, as a temporary workaround, consider restricting access to the Plugins Page or validating the pluginThemeUrl parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-41305

Affected Products

Wondercms