{ "id": "CVE-2024-27561", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-05T17:15:06.887", "lastModified": "2024-03-05T18:50:18.333", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter." }, { "lang": "es", "value": "Server-Side Request Forgery (SSRF) en la funci\u00f3n installUpdateThemePluginAction de WonderCMS v3.1.3 permite a los atacantes forzar a la aplicaci\u00f3n a realizar solicitudes arbitrarias mediante la inyecci\u00f3n de URL manipuladas en el par\u00e1metro installThemePlugin." } ], "metrics": {}, "references": [ { "url": "https://github.com/zer0yu/CVE_Request/blob/master/WonderCMS/wondercms_installUpdateThemePluginAction_plugins.md", "source": "cve@mitre.org" } ] }