# N/A
## 漏洞概述
Wonder CMS 从 v.3.2.0 到 v.3.4.2 版本中存在跨站脚本(XSS)漏洞,允许远程攻击者通过上传恶意脚本到 `installModule` 组件来执行任意代码。
## 影响版本
- v.3.2.0 到 v.3.4.2
## 漏洞细节
攻击者可以通过上传一个经过精心构造的脚本到 `installModule` 组件中,从而利用 XSS 漏洞执行任意指令。
## 漏洞影响
成功利用此漏洞可能使攻击者执行任意代码,从而控制受影响的应用程序组件。这可能引起多个安全威胁,包括用户会话劫持、敏感信息泄露等。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | WonderCMS Authenticated RCE - CVE-2023-41425 | https://github.com/prodigiousMind/CVE-2023-41425 | POC详情 |
2 | Wonder CMS RCE (XSS) | https://github.com/charlesgargasson/CVE-2023-41425 | POC详情 |
3 | WonderCMS RCE CVE-2023-41425 | https://github.com/insomnia-jacob/CVE-2023-41425 | POC详情 |
4 | Research | https://github.com/tiyeume25112004/CVE-2023-41425 | POC详情 |
5 | Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component. | https://github.com/thefizzyfish/CVE-2023-41425-wonderCMS_RCE | POC详情 |
6 | None | https://github.com/Raffli-Dev/CVE-2023-41425 | POC详情 |
7 | CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike. | https://github.com/duck-sec/CVE-2023-41425 | POC详情 |
8 | CVE-2023-41425 Refurbish | https://github.com/TanveerS1ngh/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425 | POC详情 |
9 | Writing one because the one I found isn't working | https://github.com/h3athen/CVE-2023-41425 | POC详情 |
10 | CVE-2023-41425 Refurbish | https://github.com/0xDTC/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-41425 | POC详情 |
11 | Xss injection, WonderCMS 3.2.0 -3.4.2 | https://github.com/Diegomjx/CVE-2023-41425-WonderCMS-Authenticated-RCE | POC详情 |
12 | CVE-2023-41425 (XSS to RCE, Wonder CMS 3.2.0 <= 3.4.2) | https://github.com/0x0d3ad/CVE-2023-41425 | POC详情 |
13 | Research | https://github.com/SpycioKon/CVE-2023-41425 | POC详情 |
14 | Wonder CMS v3.2.0 - v3.4.2 XSS to RCE exploit | https://github.com/xpltive/CVE-2023-41425 | POC详情 |
15 | None | https://github.com/samu21req/CVE-2023-41425 | POC详情 |
16 | None | https://github.com/KGorbakon/CVE-2023-41425 | POC详情 |
17 | WonderCMS RCE CVE-2023-41425 | https://github.com/Twappz/CVE-2023-41425 | POC详情 |