Record summary

CVE-2020-28976 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)ExploitDB exploitby Pankaj VermaNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Canto 1.3.0 - Blind Server-Side Request ForgeryCVSS 5.3

WordPress Canto plugin 1.3.0 is susceptible to blind server-side request forgery. An attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could result in unauthorized access to sensitive internal resources and potential data leakage.

Remediation

Update WordPress Canto to the latest version (1.3.1) or apply the patch provided by the vendor.

WeaknessesCWE-918
AuthorsLogicalHunter
Template tagscve2020cvepacketstormssrfwordpresswp-pluginoastedbcantovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:canto:canto:1.3.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

6