Record summary

CVE-2020-22841 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBb2evolution 6.11.6 - 'plugin name' Stored XSSExploitDB exploitby Soham BakoreNot analyzed1 file
ExploitDB

PoC details

References

4