CVE-2017-14522
26.01.2018, 20:29
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website
Vendor | Product | Version |
---|---|---|
wondercms | wondercms | 2.3.1 |
𝑥
= Vulnerable software versions