CVE-2023-3219


EventON < 2.1.2 - Unauthenticated Post Access via IDOR

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.



We have discovered 61 live websites that are affected by CVE-2023-3219.

Contact us to get more info




Affected Software

Product  EventOn
Category Appointment Scheduling
Vulnerable Versions
  • from 0 before 2.1.2
Total Vulnerable Versions194
Vulnerable Domains61 live websites (0.37% of EventOn install base)


Common Weakness Enumeration


CWE-639 Authorization Bypass Through User-Controlled Key


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-3219 and the relative popularity of websites


Details

  • Published - Jul 10, 2023
  • Updated - Jul 10, 2023

Credits

  • Miguel Santareno (finder)
  • WPScan (coordinator)





Countries

United States16 websites



France11 websites
Germany7 websites
Spain5 websites
Italy4 websites
Austria3 websites
Netherlands3 websites
Bulgaria1 websites
Switzerland1 websites
Chile1 websites

TLDs

.com24 websites
.fr8 websites
.de6 websites
.es3 websites
.nl3 websites
.at2 websites
.it2 websites
.net2 websites
.cz1 websites
.eu1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-3219 through included software libraries and plugins.



References


Websites affected by CVE-2023-3219

Top websites that are affected by CVE-2023-3219. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.hu Hungary**,***
****.**********.com United States*,***,***
***.*******.at Austria*,***,***
***.***********.cl Chile*,***,***
***.***********.fr France*,***,***
***************.de Germany*,***,***
************************.at Austria*,***,***
***.*****************.it Italy*,***,***
***.*************.fr France*,***,***
*****.fr France*,***,***
See full domain list