Cross-Site Scripting Vulnerability in WonderCMS by WonderCMS
CVE-2024-32338

5.4MEDIUM

Key Information:

Vendor

WonderCMS

Status
Vendor
CVE Published:
17 April 2024

What is CVE-2024-32338?

A cross-site scripting vulnerability present in the Settings section of WonderCMS allows attackers to inject malicious scripts through a specifically crafted payload in the PAGE TITLE parameter under the Current Page module. This flaw could enable unauthorized users to execute arbitrary web scripts or HTML, potentially compromising the integrity of a site and impacting end-users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.