mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
27 lines
1.1 KiB
Markdown
27 lines
1.1 KiB
Markdown
### [CVE-2020-13700](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13700)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that reads sensitive information in the wp_options table, such as the login and pass values.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/0xget/cve-2001-1473
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/ARPSyndicate/kenzer-templates
|
|
- https://github.com/Elsfa7-110/kenzer-templates
|
|
- https://github.com/StarCrossPortal/scalpel
|
|
- https://github.com/afine-com/research
|
|
- https://github.com/afinepl/research
|
|
- https://github.com/anonymous364872/Rapier_Tool
|
|
- https://github.com/apif-review/APIF_tool_2024
|
|
- https://github.com/youcans896768/APIV_Tool
|
|
|