Cross-Site Scripting Vulnerability in WonderCMS
CVE-2024-32744
Currently unrated
Key Information:
What is CVE-2024-32744?
A cross-site scripting vulnerability exists in the Settings section of WonderCMS version 3.4.3. This issue permits attackers to execute unauthorized web scripts or HTML within the application. By crafting a malicious payload and injecting it into the PAGE KEYWORDS parameter, an attacker can potentially manipulate the CURRENT PAGE module, leading to unauthorized actions and data exposure. This vulnerability underscores the importance of securing web applications against XSS attacks to protect user data and maintain the integrity of web resources.