Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown
CVE-2022-44036
Disclosure Date: January 03, 2023 (last updated November 08, 2023)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
0
Attacker Value
Unknown
CVE-2022-30935
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.
0
Attacker Value
Unknown
CVE-2021-31632
Disclosure Date: December 06, 2021 (last updated October 07, 2023)
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
0
Attacker Value
Unknown
CVE-2021-31631
Disclosure Date: December 06, 2021 (last updated October 07, 2023)
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
0
Attacker Value
Unknown
CVE-2021-28242
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
0
Attacker Value
Unknown
CVE-2020-22839
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
0
Attacker Value
Unknown
CVE-2020-22841
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
0
Attacker Value
Unknown
CVE-2020-22840
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
0
Attacker Value
Unknown
CVE-2016-8901
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
0
Attacker Value
Unknown
CVE-2017-1000423
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
0