CVE-2023-2796
EventON < 2.1.2 - Unauthenticated Event Access
Record summary
CVE-2023-2796 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
EventONDefault status: unaffected | CVE List | Before 2.1.2 | affected |
eventonBrowse myeventon / eventon | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin EventON Calendar 4.4 - Unauthenticated Event AccessExploitDB exploitby Miguel SantarenoNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMEventON <= 2.1 - Missing AuthorizationCVSS 5.3
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Impact
Unauthenticated users can perform privileged actions, potentially leading to unauthorized access or modification of events.
Remediation
Fixed in version 2.1.2
Source: ProjectDiscovery