First published: Tue Feb 09 2021(Updated: )
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
B2evolution | =6.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22839 is considered a medium severity vulnerability due to its potential for enabling remote code execution via XSS.
To fix CVE-2020-22839, update your b2evolution CMS to version 6.11.7 or later.
The impact of CVE-2020-22839 includes the potential for attackers to inject malicious scripts and execute them in the context of authenticated users.
CVE-2020-22839 affects users of b2evolution CMS version 6.11.6.
Implementing input validation and output encoding can help mitigate the risk posed by CVE-2020-22839.