ZeroHour

CVE-2024-41305

PoC
CVSS 3.1
4.7 medium
EPSS
<1%p8
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

Vendors
wondercms
Products
wondercms
Weakness
CWE-918, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.