CVE-2024-0868
coreActivity < 2.1 - Unauthenticated IP Spoofing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value
El complemento coreActivity: Activity Logging plugin for WordPress anterior a 2.1 recuperaba direcciones IP de solicitudes a través de encabezados como X-FORWARDED para registrarlas, lo que permitía a los usuarios falsificarlas proporcionando un valor arbitrario.
The coreActivity: Activity Logging plugin for WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.1 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to spoof their IP address.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-01-24 CVE Reserved
- 2024-03-27 CVE Published
- 2024-04-17 EPSS Updated
- 2024-08-09 CVE Updated
- 2024-08-09 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-348: Use of Less Trusted Source
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/bb7c2d2b-cdfe-433b-96cf-714e71d12b22 | 2024-08-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | CoreActivity Activity Logging Plugin For WordPress Search vendor "Unknown" for product "CoreActivity Activity Logging Plugin For WordPress" | < 2.1 Search vendor "Unknown" for product "CoreActivity Activity Logging Plugin For WordPress" and version " < 2.1" | en |
Affected
|