Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WonderCMS 代码问题漏洞
Vulnerability Description
WonderCMS是一套基于PHP的开源内容管理系统(CMS)。 WonderCMS 3.1.3 存在代码问题漏洞,该漏洞源于index.php的addCustomThemePluginRepository函数的服务器端请求伪造(SSRF),允许远程攻击者可利用该漏洞通过一个精心制作的主题插件安装程序URL执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A