A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
History

Thu, 08 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-07-30T00:00:00

Updated: 2024-08-02T04:46:52.073Z

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41305

cve-icon Vulnrichment

Updated: 2024-07-30T18:27:30.632Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-30T18:15:05.910

Modified: 2024-08-08T14:36:06.423

Link: CVE-2024-41305

cve-icon Redhat

No data.