CVE-2018-1000062
Dashboard / Vulnerabilities / CVE-2018-1000062
CVE-2018-1000062
Published: 9 Feb 2018Last Modified: 27 Aug 2026
Summary:
Details: WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File.
References: https://github.com/robiso/wondercms/issues/56, https://github.com/robiso/wondercms/blob/ea640a02b4b8d88835d2e01600d24b23176fb665/index.php#L737
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 8aec5e9a3aa9eed568e0552abe0830e00bb63bf7
Fixed -None
Affected versions
2.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
