CVE-2020-28976 | Canto Plugin 1.3.0 on WordPress /includes/lib/detail.php subdomain server-side request forgery (EDB-49189)
A vulnerability classified as critical has been found in Canto Plugin 1.3.0 on WordPress. Affected is an unknown function of the file /includes/lib/detail.php. The manipulation of the argument subdomain leads to server-side request forgery.
This vulnerability is traded as CVE-2020-28976. The attack needs to be approached within the local network. Furthermore, there is an exploit available.