CVE-2023-2796
MEDIUM EXPLOITED NUCLEIEventON < 2.1.2 - Unauthenticated Insecure Direct Object Reference via eventon_ics_download AJAX Action
Title source: llmExploitation Summary
CVE-2023-2796 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Miguel Santareno. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in the EventON Calendar WordPress plugin. By manipulating the 'event_id' parameter in an AJAX request, attackers can access private or password-protected events without authentication.
Description
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Exploits (1)
This exploit demonstrates an unauthenticated information disclosure vulnerability in the EventON Calendar WordPress plugin. By manipulating the 'event_id' parameter in an AJAX request, attackers can access private or password-protected events without authentication.
Nuclei Templates (1)
vuln:CVE-2023-2796 || http.html:/wp-content/plugins/eventon-lite/ || http.html:/wp-content/plugins/eventon/
wp-content/plugins/eventon/ || body=/wp-content/plugins/eventon/ || body=/wp-content/plugins/eventon-lite/
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N