AI Score
Confidence
High
EPSS
Percentile
64.8%
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
github.com/verbb/knock-knock
github.com/verbb/knock-knock/blob/craft-3/CHANGELOG.md
limpidsecurity.pl/security-advisories/1/knock-knock-plugin-for-craft-cms
nvd.nist.gov/vuln/detail/CVE-2020-13485