github.com
https://github.com/robiso/wondercms CVE-2020-35314
CRITICAL
WonderCMS 3.1.3 - Authenticated Remote Code Execution
Record summary
CVE-2020-35314 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBWonderCMS 3.1.3 - Authenticated Remote Code ExecutionExploitDB exploitby zetc0deNot analyzed1 file
Repository PoCs
GitHubybdegit2020/wonderpluginRepository PoCby ybdegit2020Stars: 0Not analyzed6 files
GitHubAkashLingayat/WonderCMS-CVE-2020-35314Repository PoCby AkashLingayatStars: 0Not analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35314 packetstormsecurity.com
https://packetstormsecurity.com/files/160311/WonderCMS-3.1.3-Remote-Code-Execution.html zetc0de.github.io
https://zetc0de.github.io/post/authenticated-rce-ssrf-wondercms