Server-Side Request Forgery in WonderCMS affects user data and security
CVE-2024-27563
5.3MEDIUM
Key Information:
What is CVE-2024-27563?
A vulnerability exists in WonderCMS that allows attackers to exploit the getFileFromRepo function. By injecting carefully crafted URLs into the pluginThemeUrl parameter, an attacker may force the application to make arbitrary HTTP requests to potentially sensitive services, which could lead to unauthorized access and data exposure.