CVE-2023-41425 affects WonderCMS versions 3.2.0 through 3.4.2. The provided content describes it as a cross-site scripting issue in the installModule component, and also notes Metasploit support targeting the issue as a file-upload-driven remote code execution path. Based on the supplied description, a remote attacker can leverage crafted script content associated with installModule to execute arbitrary code. The supporting content further indicates exploitation involves authenticating to a vulnerable WonderCMS instance with a password, creating a ZIP archive containing a malicious PHP file, uploading it, and having the archive parsed into the /themes directory where the PHP payload is then executed by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a fully operational exploit for CVE-2023-41425, a remote code execution vulnerability in WonderCMS 4.3.2. The main exploit script (exploit_CVE-2023-41425.py) automates the process of generating a malicious ZIP theme module containing a PHP reverse shell (reverseShell.php), crafting a JavaScript XSS payload to hijack an admin session, and hosting the necessary files via a local HTTP server. The workflow is as follows: the attacker customizes the reverse shell with their IP and port, packages it into a ZIP, and generates a JS payload that, when executed in the admin's browser (via XSS), installs the malicious theme and triggers the reverse shell, granting the attacker remote access. The exploit requires the attacker to deliver the XSS payload to an admin user and to host the ZIP and JS files on a server accessible to the target. The repository is well-structured, with clear separation between the exploit logic (Python), the payload (PHP), and documentation (README.md).
This repository contains a single Metasploit module (modules/exploits/multi/http/wondercms_rce.rb) that exploits CVE-2023-41425, an authenticated file upload vulnerability in WonderCMS versions 3.2.0 to 3.4.2. The exploit requires valid credentials to log in to the target WonderCMS instance. It works by creating a malicious ZIP file containing a PHP payload, which is then served via an HTTP server controlled by the attacker. The module uses WonderCMS's module installation feature to upload and extract the ZIP file, placing the PHP payload in the /themes directory. Finally, the exploit triggers the payload by sending a request to the uploaded PHP file, resulting in remote code execution. The module is weaponized, supporting customizable payloads (defaulting to php/meterpreter/reverse_tcp) and includes cleanup options. The main attack vector is network-based, targeting HTTP endpoints exposed by WonderCMS. The code is structured as a standard Metasploit exploit module, with clear separation of login, check, payload creation, and exploitation logic.
This repository contains a single Nmap NSE script (cve-2023-41425.nse) targeting WonderCMS 3.4.2 for CVE-2023-41425, a reflected XSS vulnerability that can be leveraged for remote code execution (RCE). The script constructs an XSS payload that injects a script tag referencing attacker-controlled JavaScript. If the target is vulnerable, this can lead to the installation of a malicious module and the deployment of a webshell at /themes/pwned/malicious.php. The script checks for the vulnerability by sending a request to the /index.php?page=loginURL? endpoint and looking for a reflected form. The repository is a proof-of-concept exploit and does not include a full payload or webshell, but provides the necessary XSS vector for further exploitation.
This repository provides an operational exploit for CVE-2023-41425, a reflected XSS vulnerability in Wonder CMS versions 3.2.0 to 3.4.2. The exploit chain leverages XSS to execute arbitrary JavaScript in the victim's browser, which then abuses the 'installModule' functionality to install a malicious ZIP file containing a PHP web shell on the target server. The attacker hosts both a malicious JavaScript file and a ZIP archive with the web shell. The exploit script (exploit.py) automates the creation of these files and provides the necessary XSS payload to trigger the attack. Once the victim accesses the crafted XSS URL, the malicious JavaScript is loaded, resulting in the installation of the web shell. The attacker can then execute arbitrary commands or obtain a reverse shell via the web shell endpoint. The repository consists of a Python exploit script, a requirements file, and a detailed README with usage instructions and example payloads. The main attack vectors are network-based (HTTP) and browser-based (XSS). Several fingerprintable endpoints are present, including the target's login URL, the attacker's hosted files, and the web shell endpoint.
This repository contains an exploit for CVE-2023-41425, targeting WonderCMS versions 3.2.0 through 3.4.2. The exploit leverages a reflected XSS vulnerability in the installModule component to achieve remote code execution. The main file, exploit.py, automates the attack by generating a malicious JavaScript payload (xss.js) and serving it via a local HTTP server. The attacker sends a crafted link to a WonderCMS admin; when clicked, the admin's browser executes the XSS payload, which abuses the installModule feature to upload a reverse shell (revshell-main.zip) to the target. The payload is then triggered, granting the attacker a reverse shell. The repository structure is simple, with a README.md providing detailed usage instructions and exploit.py implementing the attack logic. The exploit requires the attacker to host files and have the admin interact with the malicious link, and it provides a direct reverse shell if successful. Several fingerprintable endpoints are present, including the URLs for the payload delivery and the reverse shell trigger.
This repository contains two Bash scripts (AUTO_CVE-2023-41425 and CVE-2023-41425) and a README.md, all focused on exploiting CVE-2023-41425 in WonderCMS 4.3.2. The exploit leverages a stored XSS vulnerability in the contact form to achieve remote code execution (RCE) by installing a malicious theme module containing a PHP reverse shell. The scripts automate the process of generating the payload (downloading a PHP reverse shell from revshells.com, customizing it with the attacker's IP and port, and packaging it as a ZIP), hosting it via a Python HTTP server, and injecting the XSS payload into the target. The automatic script (AUTO_CVE-2023-41425) further checks for a running netcat listener and sends the XSS payload automatically, while the manual script (CVE-2023-41425) requires the user to send the crafted link to the admin. Both scripts require the admin to trigger the XSS for the exploit to succeed. The repository is a functional proof-of-concept for XSS-to-RCE exploitation against WonderCMS 4.3.2, and is not part of a larger exploit framework.
This repository contains a working exploit for CVE-2023-41425, a Cross-Site Scripting (XSS) to Remote Code Execution (RCE) vulnerability in WonderCMS versions 3.2.0 to 3.4.2 (and possibly 4.3.2 as per the exploit script). The exploit consists of a Python script (exploit.py) that generates a tailored JavaScript payload (xss.js) based on user-supplied parameters (target URL, attacker's IP/port, etc.). The attacker serves xss.js and a malicious module (main.zip, not included in the repo) via a local HTTP server. The attack flow is as follows: 1. The attacker crafts a malicious XSS link and sends it to an authenticated admin user of the target WonderCMS instance. 2. When the admin visits the link, the injected JavaScript (xss.js) is loaded from the attacker's server. 3. The script abuses the installModule functionality to install a malicious module (main.zip) from the attacker's server. 4. The script then triggers a PHP reverse shell (rev.php) on the target, connecting back to the attacker's listener (netcat). The repository includes: - README.md: Detailed usage instructions, example output, and background. - exploit.py: The main exploit script, which generates the payload and serves it. - xss.js: Example JavaScript payload (overwritten by exploit.py during use). The exploit is operational and provides a reverse shell as www-data on the target. It requires the attacker to host files locally and to have the admin user visit a crafted link. The exploit is not part of a framework and is self-contained.
This repository provides a working exploit for CVE-2023-41425, a Cross-Site Scripting (XSS) vulnerability in Wonder CMS versions 3.2.0 through 3.4.2 that can be leveraged for remote code execution (RCE). The main exploit script (CVE-2023-41425.py) automates the attack by: 1. Creating a ZIP archive containing a simple PHP webshell (shell/shell.php). 2. Generating a malicious JavaScript payload (xss.js) that, when executed in an admin's browser, abuses the installModule feature to upload the webshell to the target server from the attacker's HTTP server. 3. Instructing the attacker to send a crafted XSS URL to the victim (admin) or use it themselves if they have access. 4. Hosting the malicious files via a local HTTP server. 5. Once the webshell is uploaded, the script triggers it to execute a reverse shell command, connecting back to the attacker's netcat listener. The exploit requires knowledge of the target's login URL and either admin access or the ability to get an admin to click the XSS link. The repository contains two main code files: the Python exploit script and the PHP webshell. The attack vector is network-based, exploiting a web application endpoint. The exploit is operational, providing a working RCE chain but requiring some manual steps and setup.
This repository contains an exploit for CVE-2023-41425, a Cross-Site Scripting (XSS) to Remote Code Execution (RCE) vulnerability in WonderCMS versions 3.2.0 through 3.4.2. The exploit consists of a Python script (exploit.py) that generates a malicious JavaScript file (xss.js) designed to be delivered to a logged-in admin user. When the admin visits the crafted link, the JavaScript abuses the admin's session to install a malicious theme (containing a PHP reverse shell) via the installModule component, then triggers the shell with attacker-supplied parameters, resulting in a reverse shell connection to the attacker's machine. The repository structure is simple, with a README.md explaining the vulnerability and usage, and exploit.py implementing the attack logic. The exploit requires the attacker to serve xss.js and listen for a reverse shell connection, and leverages both browser-based and network attack vectors. Key endpoints include the attacker's HTTP server for xss.js, the GitHub URL hosting the malicious theme, and the reverse shell endpoint on the target.
This repository provides a working exploit for CVE-2023-41425, a vulnerability in WonderCMS versions 3.2.0 through 3.4.2 that allows an attacker to achieve remote code execution (RCE) via a cross-site scripting (XSS) vector. The exploit consists of a Python script (exploit.py) that generates a JavaScript payload (xss.js). The attack flow is as follows: the attacker crafts a malicious URL containing a script tag that loads the attacker's xss.js from their own HTTP server. When an administrator visits this URL, the JavaScript payload triggers the installation of a malicious theme (hosted by the attacker) containing a PHP webshell. The script then uses the webshell to execute arbitrary commands, including spawning a reverse shell to the attacker's machine. The README.md provides detailed instructions, including how to set up the HTTP server, craft the payload, and use the webshell. Additionally, the exploit includes a payload for stealing administrator session cookies. The repository is well-structured, with clear separation between the exploit logic (exploit.py), the generated payload (xss.js), and documentation (README.md).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.