Record summary

CVE-2020-29247 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWonderCMS 3.1.3 - 'page' Persistent Cross-Site ScriptingExploitDB exploitby Mayur ParmarNot analyzed1 file
ExploitDB

PoC details

References

4