mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
20 lines
850 B
Markdown
20 lines
850 B
Markdown
### [CVE-2024-3050](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3050)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass IP-based blocking
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/04c1581e-fd36-49d4-8463-b49915d4b1ac/
|
|
|
|
#### Github
|
|
- https://github.com/DojoSecurity/DojoSecurity
|
|
- https://github.com/afine-com/research
|
|
- https://github.com/vemusx/vemusx
|
|
|