wondercms.com
http://wondercms.com/ CVE-2020-29247
MEDIUM
WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
Record summary
CVE-2020-29247 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWonderCMS 3.1.3 - 'page' Persistent Cross-Site ScriptingExploitDB exploitby Mayur ParmarNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29247 systemweakness.com
https://systemweakness.com/cve-2020-29247-wondercms-3-1-3-page-persistent-cross-site-scripting-3dd2bb210beb exploit-db.com
https://www.exploit-db.com/exploits/49102