Логотип exploitDog
bind:CVE-2024-58305
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-58305

Количество 2

Количество 2

nvd логотип

CVE-2024-58305

около 2 месяцев назад

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgm3-gj32-7f57

около 2 месяцев назад

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-58305

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xgm3-gj32-7f57

WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу