Record summary

CVE-2020-35314 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.

Description

A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2

Proofs of concept

3

Catalogued exploits

ExploitDBWonderCMS 3.1.3 - Authenticated Remote Code ExecutionExploitDB exploitby zetc0deNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubybdegit2020/wonderpluginRepository PoCby ybdegit2020Stars: 0Not analyzed6 files

102.8 KiB

GitHub

PoC details
GitHubAkashLingayat/WonderCMS-CVE-2020-35314Repository PoCby AkashLingayatStars: 0Not analyzed1 file

525 B

GitHub

PoC details

References

4