CVE-2020-24063 – Canto <= 1.9.0 - Blind Server-Side Request Forgery via download.php
https://notcve.org/view.php?id=CVE-2020-24063
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. El plugin Canto versión 1.3.0, para WordPress permite un ataque SSRF en includes/lib/download.php?subdomain= The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF. • https://gist.github.com/Hakooraevil/264cb21034f946eee62371e9111c36bb https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2020-28977 – Canto <= 1.9.0 - Blind Server-Side Request Forgery via get.php
https://notcve.org/view.php?id=CVE-2020-28977
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF. El plugin Canto versión 1.3.0 para WordPress, contiene una vulnerabilidad de tipo SSRF ciega. Permite a un atacante no autenticado poder realizar una petición a cualquier servidor interno y externo por medio de /includes/lib/get.php? • https://www.exploit-db.com/exploits/49189 http://packetstormsecurity.com/files/160358/WordPress-Canto-1.3.0-Server-Side-Request-Forgery.html https://gist.github.com/p4nk4jv/87aebd999ce4b28063943480e95fd9e0 https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2020-28978 – Canto <= 1.9.0 - Blind Server-Side Request Forgery via tree.php
https://notcve.org/view.php?id=CVE-2020-28978
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF. El plugin Canto versión 1.3.0 para WordPress, contiene una vulnerabilidad de tipo SSRF ciega. Permite a un atacante no autenticado poder realizar una petición a cualquier servidor interno y externo por medio de /includes/lib/tree.php? • https://www.exploit-db.com/exploits/49189 http://packetstormsecurity.com/files/160358/WordPress-Canto-1.3.0-Server-Side-Request-Forgery.html https://gist.github.com/p4nk4jv/87aebd999ce4b28063943480e95fd9e0 https://github.com/CantoDAM/Canto-Wordpress-Plugin https://wordpress.org/plugins/canto/#developers https://www.canto.com/integrations/wordpress • CWE-918: Server-Side Request Forgery (SSRF) •