Record summary

CVE-2023-3219 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

EventON

Default status: unaffected

CVE ListBefore 2.1.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDORExploitDB exploitby Miguel SantarenoNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMEventON Lite < 2.1.2 - Arbitrary File DownloadCVSS 5.3

The plugin does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

Impact

Unauthenticated attackers can exploit missing validation in the eventon_ics_download AJAX action to access any post content including unpublished or protected posts through ICS export functionality.

Remediation

Fixed in version 2.1.2

WeaknessesCWE-639
Authorsr3Y3r53
Template tagscvecve2023wpscanpacketstormwordpresswp-pluginwpeventon-litebypassmyeventonvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/eventon/
Shodan: http.html:/wp-content/plugins/eventon-lite/
FOFA: wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon/
FOFA: body=/wp-content/plugins/eventon-lite/
Google: inurl:"/wp-content/plugins/eventon/"

Source: ProjectDiscovery

References

3