CVE-2023-41425
About
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
Rainforest analyst review
WonderCMS versions 3.2.0 through 3.4.2 carry a cross-site scripting flaw in the installModule component: a crafted script routed through that component executes in a victim's browser in the site's context. Delivered against an authenticated administrator, XSS in an admin surface is the dangerous case — it can ride the admin's session to perform privileged actions, and in a CMS that often means a path toward fuller control of the site.
The tempering factor is that this needs the victim to interact and the scope change reflects it crossing into the browser's trust context, so it isn't a fire-and-forget server exploit. The realistic scenario is an attacker luring or coaxing an admin into triggering the payload. That's a real but conditional threat, not the indiscriminate mass-exploitation you see with unauthenticated server-side bugs.
We hold this at its medium rating and treat it as a candidate for chaining rather than a standalone crisis: admin-context XSS is most dangerous as the first link toward session hijack or configuration change. Our practical steps are identifying WonderCMS instances in the vulnerable range and applying browser-side and detection controls around the admin panel, while prioritizing the unauthenticated RCEs in this same batch ahead of it.
References
Related CVEs
Frequently asked questions
What is CVE-2023-41425?
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
How severe is CVE-2023-41425?
CVE-2023-41425 carries a CVSS 3.1 base score of 6.1, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 67 out of 100, in the elevated band.
How is CVE-2023-41425 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction Required. Impact on confidentiality Low, integrity Low and availability None.
Which products are affected by CVE-2023-41425?
Public advisories list the following as affected: wondercms. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-41425?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
