PT-2021-10799 · Unknown · B2Evolution Cms
Nakul Ratti
+1
·
Published
2021-02-09
·
Updated
2021-02-17
·
CVE-2020-22840
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
b2evolution CMS versions prior to 6.11.6
Description
The issue allows an attacker to perform malicious open redirects to an attacker-controlled resource via the
redirect to parameter in email passthrough.php.Recommendations
For versions prior to 6.11.6, update to version 6.11.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
email passthrough.php file or disabling the redirect to parameter until a patch is available.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B2Evolution Cms