vendor:
WonderCMS
by:
zetc0de
9.8
CVSS
CRITICAL
Authenticated Remote Code Execution
78
CWE
Product Name: WonderCMS
Affected Version From: 3.1.3
Affected Version To: 3.1.3
Patch Exists: YES
Related CWE: CVE-2020-35314
CPE: a:wondercms:wondercms:3.1.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04
2020
WonderCMS 3.1.3 – Authenticated Remote Code Execution
WonderCMS is vulnerable to Authenticated Remote Code Execution. In order to exploit the vulnerability, an attacker must have a valid authenticated session on the CMS. Using the theme/plugin installer attacker can install crafted plugin that contain a webshell and get RCE.
Mitigation:
Ensure that all users have strong passwords and that they are not shared with anyone. Ensure that all users are using the latest version of the CMS and that all security patches are applied.