PT-2020-13568 · Craft Cms · Knock Knock

Paweł Hałdrzyński

·

Published

2020-05-25

·

Updated

2022-05-24

·

CVE-2020-13485

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Knock Knock plugin versions prior to 1.2.8
Description The issue allows IP Whitelist bypass via an X-Forwarded-For HTTP header. This means that an attacker can potentially bypass the IP whitelist by manipulating the X-Forwarded-For header in HTTP requests.
Recommendations For versions prior to 1.2.8, update to version 1.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the Craft CMS to minimize the risk of exploitation. Avoid relying solely on the IP Whitelist for security until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13485
GHSA-WXVR-QQM7-6H65

Affected Products

Knock Knock