CVE-2024-0236

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*

History

19 Jan 2024, 14:28

Type Values Removed Values Added
Summary
  • (es) El complemento EventON WordPress anterior a 4.5.5 y el complemento EventON WordPress anterior a 2.2.7 no tienen autorización en una acción AJAX, lo que permite a usuarios no autenticados recuperar la configuración de eventos virtuales arbitrarios, incluida cualquier contraseña de reunión establecida (por ejemplo, para Zoom).
CWE CWE-862
First Time Myeventon
Myeventon eventon
References () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - () https://wpscan.com/vulnerability/09aeb6f2-6473-4de7-8598-e417049896d7/ - Third Party Advisory
CPE cpe:2.3:a:myeventon:eventon:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

16 Jan 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 16:15

Updated : 2024-01-19 14:28


NVD link : CVE-2024-0236

Mitre link : CVE-2024-0236

CVE.ORG link : CVE-2024-0236


JSON object : View

Products Affected

myeventon

  • eventon
CWE
CWE-862

Missing Authorization