Cross-Site Scripting Vulnerability in WonderCMS by WonderCMS
CVE-2020-29233

5.4MEDIUM

Key Information:

Vendor

Wondercms

Status
Vendor
CVE Published:
30 December 2020

What is CVE-2020-29233?

WonderCMS version 3.1.3 is susceptible to a cross-site scripting (XSS) vulnerability in the Page description component. This flaw enables an attacker to inject a malicious payload into the page description, which can be executed whenever any user visits the affected website. The executed script can lead to the theft of cookies and other sensitive data, thus compromising user sessions and website integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-29233 : Cross-Site Scripting Vulnerability in WonderCMS by WonderCMS