Cross-Site Scripting Vulnerability in WonderCMS by WonderCMS
CVE-2020-29233
5.4MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2020-29233?
WonderCMS version 3.1.3 is susceptible to a cross-site scripting (XSS) vulnerability in the Page description component. This flaw enables an attacker to inject a malicious payload into the page description, which can be executed whenever any user visits the affected website. The executed script can lead to the theft of cookies and other sensitive data, thus compromising user sessions and website integrity.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
