In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://securitywarrior9.blogspot.in/2018/01/vulnerability-in-wonder-cms-leading-to.html | exploit third party advisory technical description |
https://www.exploit-db.com/exploits/43963/ | exploit vdb entry third party advisory |