CVE-2023-41425
MEDIUM 6.1EPSS 54.0%
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS
- 54.03% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2023-11-07
- Updated
- 2026-07-09
Proof-of-concept exploits (20)
- https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413
- 0x0d3ad/CVE-2023-414250★ · 2024-11-30
- 0xDTC/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-414250★ · 2025-01-07
- Diegomjx/CVE-2023-41425-WonderCMS-Authenticated-RCE1★ · 2025-01-19
- Raffli-Dev/CVE-2023-414251★ · 2024-09-03
- RenannLimaa/WonderCMS-3.2.0-exploit0★ · 2025-01-15
- SpycioKon/CVE-2023-414250★ · 2024-08-22
- TanveerS1ngh/WonderCMS-4.3.2-XSS-to-RCE-Exploits-CVE-2023-414250★ · 2025-01-07
- Tea-On/CVE-2023-41425-RCE-WonderCMS-4.3.28★ · 2025-07-16
- Twappz/CVE-2023-414250★ · 2024-08-12
- becrevex/CVE-2023-414250★ · 2025-04-25
- charlesgargasson/CVE-2023-414251★ · 2024-08-11
- dgthegeek/htb-sea0★ · 2024-12-15
- duck-sec/CVE-2023-414253★ · 2024-10-02
- h3athen/CVE-2023-414250★ · 2024-10-30
- prodigiousMind/CVE-2023-4142527★ · 2024-12-30
- thefizzyfish/CVE-2023-41425-wonderCMS_RCE2★ · 2024-10-03
- tiyeume25112004/CVE-2023-414250★ · 2024-08-22
- xpltive/CVE-2023-414251★ · 2024-12-23
- wnaspy/CVE-POC-WEAPON