Themes Vulnerabilities

Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts Disclosure

Description

The theme allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.

Proof of Concept

Affects Themes

Fixed in 3.0.4

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Emil Kylander Edwartz
Submitter
Emil Kylander Edwartz
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-10-11 (about 4 years ago)
Added
2021-10-11 (about 4 years ago)
Last Updated
2022-04-08 (about 3 years ago)

Other