Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown

CVE-2022-44036

Disclosure Date: January 03, 2023 (last updated November 08, 2023)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Attacker Value
Unknown

CVE-2022-30935

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.
Attacker Value
Unknown

CVE-2021-31632

Disclosure Date: December 06, 2021 (last updated October 07, 2023)
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
Attacker Value
Unknown

CVE-2021-31631

Disclosure Date: December 06, 2021 (last updated October 07, 2023)
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Attacker Value
Unknown

CVE-2021-28242

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.
Attacker Value
Unknown

CVE-2020-22839

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
Attacker Value
Unknown

CVE-2020-22841

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
Attacker Value
Unknown

CVE-2020-22840

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
Attacker Value
Unknown

CVE-2016-8901

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
0
Attacker Value
Unknown

CVE-2017-1000423

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
0