ZeroHour

CVE-2024-27563

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p35
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

Vendors
wondercms
Products
wondercms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.