CVE-2016-8901: Critical severity evolution vulnerability
Published May 23, 2019
·Updated
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/callplugin.php.
Affected Software
1 affected component
b2evolution b2evolution=6.7.6
Remediation
Event History
May 23, 2019
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8901?
CVE-2016-8901 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-8901?
To fix CVE-2016-8901, upgrade b2evolution to version 6.7.7 or later.
3
What causes the vulnerability in CVE-2016-8901?
CVE-2016-8901 is caused by an Object Injection vulnerability in the call_plugin.php file.
4
Is CVE-2016-8901 exploitable remotely?
Yes, CVE-2016-8901 can be exploited remotely by attackers to execute arbitrary code.
5
Which software versions are affected by CVE-2016-8901?
CVE-2016-8901 affects b2evolution version 6.7.6.