cleantalk
Vulnerabilities and Security Researches

EventON, CVE-2023-2796

CVE, Research URL

CVE-2023-2796

Application

EventON

Published on
Jul 10, 2023
Research Description
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
Affected versions
Min -, max 2.1.2.
Status
vulnerable