packetstormsecurity.com
http://packetstormsecurity.com/files/161363/b2evolution-CMS-6.11.6-Cross-Site-Scripting.html CVE-2020-22841
MEDIUM
b2evolution 6.11.6 - 'plugin name' Stored XSS
Record summary
CVE-2020-22841 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBb2evolution 6.11.6 - 'plugin name' Stored XSSExploitDB exploitby Soham BakoreNot analyzed1 file
References
4github.com
https://github.com/b2evolution/b2evolution/issues/102 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-22841 exploit-db.com
https://www.exploit-db.com/exploits/49551