Cross-Site Scripting Vulnerability in WonderCMS
CVE-2024-32744

4.6MEDIUM

Key Information:

Vendor

WonderCMS

Status
Vendor
CVE Published:
17 April 2024

What is CVE-2024-32744?

A cross-site scripting vulnerability exists in the Settings section of WonderCMS version 3.4.3. This issue permits attackers to execute unauthorized web scripts or HTML within the application. By crafting a malicious payload and injecting it into the PAGE KEYWORDS parameter, an attacker can potentially manipulate the CURRENT PAGE module, leading to unauthorized actions and data exposure. This vulnerability underscores the importance of securing web applications against XSS attacks to protect user data and maintain the integrity of web resources.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.