Security Advisory

CVE-2020-13485

9.1
CRITICAL

Vulnerability Description

The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
Published Date May 25, 2020
Official Source NIST NVD Advisory