
CVE-2023-41425
WonderCMS Authenticated RCE - CVE-2023-41425
exploitationpayload-generationphishing+3
27

WonderCMS Authenticated RCE - CVE-2023-41425

Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command…

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…