Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-41425

Description

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

POC

Reference

- https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413

- https://www.exploit-db.com/exploits/52271

Github

- https://github.com/0x0d3ad/CVE-2023-41425

- https://github.com/0xDTC/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/Diegomjx/CVE-2023-41425-WonderCMS-Authenticated-RCE

- https://github.com/PuddinCat/GithubRepoSpider

- https://github.com/Raffli-Dev/CVE-2023-41425

- https://github.com/RenannLimaa/WonderCMS-3.2.0-exploit

- https://github.com/SpycioKon/CVE-2023-41425

- https://github.com/SrcVme50/Sea

- https://github.com/TanveerS1ngh/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425

- https://github.com/Tea-On/CVE-2023-41425-RCE-WonderCMS-4.3.2

- https://github.com/Twappz/CVE-2023-41425

- https://github.com/becrevex/CVE-2023-41425

- https://github.com/charlesgargasson/CVE-2023-41425

- https://github.com/charlesgargasson/charlesgargasson

- https://github.com/dgthegeek/htb-sea

- https://github.com/duck-sec/CVE-2023-41425

- https://github.com/h3athen/CVE-2023-41425

- https://github.com/insomnia-jacob/CVE-2023-41425

- https://github.com/nomi-sec/PoC-in-GitHub

- https://github.com/plzheheplztrying/cve_monitor

- https://github.com/prodigiousMind/CVE-2023-41425

- https://github.com/thefizzyfish/CVE-2023-41425-wonderCMS_RCE

- https://github.com/tiyeume25112004/CVE-2023-41425

- https://github.com/xpltive/CVE-2023-41425

- https://github.com/zhanpengliu-tencent/medium-cve