CVE-2020-29233

Source
https://cve.org/CVERecord?id=CVE-2020-29233
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29233.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-29233
Published
2020-12-30T15:15:12.480Z
Modified
2026-07-08T19:03:22.074739Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.

References

Affected packages

Git / github.com/wondercms/wondercms

Affected ranges

Type
GIT
Repo
https://github.com/wondercms/wondercms
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:wondercms:wondercms:3.1.3:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.1.3"
        },
        {
            "last_affected": "3.1.3"
        }
    ]
}

Affected versions

3.*
3.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29233.json"