Cross-Site Scripting Vulnerability in WonderCMS by WonderCMS
CVE-2024-32337

Currently unrated

Key Information:

Vendor

WonderCMS

Status
Vendor
CVE Published:
17 April 2024

What is CVE-2024-32337?

An XSS vulnerability exists in the Settings section of WonderCMS v3.4.3, enabling attackers to run arbitrary scripts or HTML. This flaw can be exploited by injecting a crafted payload into the ADMIN LOGIN URL parameter within the Security module, potentially compromising site integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.