vendor:
WonderCMS
by:
Milad Karimi (Ex3ptionaL)
6.1
CVSS
HIGH
Remote Code Execution (RCE)
94
CWE
Product Name: WonderCMS
Affected Version From: 3.4.2002
Affected Version To: 3.4.2002
Patch Exists: YES
Related CWE: CVE-2023-41425
CPE: a:wondercms_project:wondercms:3.4.2
Platforms Tested:
2025
WonderCMS 3.4.2 – Remote Code Execution (RCE)
The WonderCMS version 3.4.2 is vulnerable to remote code execution. An attacker can exploit this vulnerability by injecting a malicious .js file through an XSS attack, leading to the execution of arbitrary PHP code on the target system. This vulnerability has been assigned CVE-2023-41425.
Mitigation:
To mitigate this vulnerability, users are advised to update WonderCMS to a patched version that addresses this issue. Additionally, input validation and output encoding should be implemented to prevent XSS attacks.