ZeroHour

CVE-2024-27561

PoC
CVSS 3.1
8.1 high
EPSS
<1%p46
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.

Vendors
wondercms
Products
wondercms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.