CVE-2020-28976
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
Record summary
CVE-2020-28976 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)ExploitDB exploitby Pankaj VermaNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Canto 1.3.0 - Blind Server-Side Request ForgeryCVSS 5.3
WordPress Canto plugin 1.3.0 is susceptible to blind server-side request forgery. An attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources and potential data leakage.
Remediation
Update WordPress Canto to the latest version (1.3.1) or apply the patch provided by the vendor.
Source: ProjectDiscovery