Cross-Site Scripting Vulnerability in WonderCMS v3.4.3
CVE-2024-32745

5.9MEDIUM

Key Information:

Vendor

WonderCMS

Status
Vendor
CVE Published:
17 April 2024

What is CVE-2024-32745?

A cross-site scripting (XSS) vulnerability has been identified in the Settings section of WonderCMS version 3.4.3. This flaw enables attackers to inject and execute arbitrary web scripts or HTML by manipulating the PAGE DESCRIPTION parameter within the CURRENT PAGE module. Such exploitation can lead to unauthorized access and compromise of user data, making it essential for users of this version to implement security best practices and apply the necessary updates.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.