
CVE-2023-41425
XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.
exploitationinformation-gatheringpayload-generation+3
1

XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance