CVE-2024-13513
CRITICALOliver POS <= 2.4.2.3 - Unauthenticated Sensitive Information Exposure via Logging
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-13513. PoCs published by 0axz-tools, KTN1990.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-13513, targeting the Oliver POS WordPress plugin. The exploit scans for vulnerable installations, extracts client tokens from log files, and performs an unauthorized email change for the admin user via a crafted HTTP request.
Description
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.
Exploits (2)
This repository contains a functional exploit for CVE-2024-13513, targeting the Oliver POS WordPress plugin. The exploit scans for vulnerable installations, extracts client tokens from log files, and performs an unauthorized email change for the admin user via a crafted HTTP request.
The repository contains a functional Python exploit for CVE-2024-13513, targeting the Oliver POS WooCommerce plugin. It extracts sensitive client tokens from log files and uses them to change user account information, leading to privilege escalation and site takeover.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H