CVE-2017-1000423

CRITICAL

b2evolution <6.8.10 - RCE

Title source: llm
STIX 2.1

Description

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.

Scores

CVSS v3 9.8
EPSS 0.0170
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
b2evolution/b2evolution 6.6.0 - 6.8.10
Published Jan 02, 2018
Tracked Since Feb 18, 2026