github.com
https://github.com/robiso/wondercms CVE-2020-35313
CRITICAL
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
Record summary
CVE-2020-35313 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code ExecutionExploitDB exploitby zetc0deNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35313 packetstormsecurity.com
https://packetstormsecurity.com/files/160310/WonderCMS-3.1.3-Code-Execution-Server-Side-Request-Forgery.html zetc0de.github.io
https://zetc0de.github.io/post/authenticated-rce-ssrf-wondercms