patrickdeanramos/WonderCMS-version-3.4.3-is-vulnerable-to-Server-Side-Request-Forgery

patrickdeanramos/WonderCMS-version-3.4.3-is-vulnerable-to-Server-Side-Request-Forgery

Releases0
WonderCMS version 3.4.3 is vulnerable to Server-Side Request Forgery (SSRF), allowing an attacker to make requests to unauthorized internal resources through the pluginThemeUrl parameter on the Plugins Page.

CVE History

CVEPublishedCVSS v3CVSS v2
4.7 MEDIUM

A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.