PT-2021-10800 · Unknown · B2Evolution Cms
Nakul Ratti
+1
·
Published
2021-02-09
·
Updated
2021-02-17
·
CVE-2020-22841
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
b2evolution CMS versions prior to 6.11.7
Description
The issue allows an attacker to execute malicious JavaScript code via the plugin name input field in the plugin module. This is a Stored XSS issue.
Recommendations
For b2evolution CMS versions prior to 6.11.7, update to version 6.11.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin module to minimize the risk of exploitation. Avoid using the plugin name input field in the plugin module until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B2Evolution Cms