2024-05-25 21:48:12 +02:00
### [CVE-2023-2796](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2796)



### Description
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.
### POC
#### Reference
- http://packetstormsecurity.com/files/173984/WordPress-EventON-Calendar-4.4-Insecure-Direct-Object-Reference.html
2024-05-28 08:49:17 +00:00
- https://wpscan.com/vulnerability/e9ef793c-e5a3-4c55-beee-56b0909f7a0d
2024-05-25 21:48:12 +02:00
#### Github
2024-07-25 21:25:12 +00:00
- https://github.com/NoTsPepino/Shodan-Dorking
2024-05-25 21:48:12 +02:00
- https://github.com/nullfuzz-pentest/shodan-dorks