VYPR
Medium severity6.1NVD Advisory· Published Nov 7, 2023· Updated Jul 9, 2026

CVE-2023-41425

CVE-2023-41425

Description

Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wondercms:wondercms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wondercms:wondercms:*:*:*:*:*:*:*:*range: >=3.2.0,<=3.4.2
    • (no CPE)range: 3.2.0-3.4.2
  • Wonder/CMSdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.