CVE-2020-22839: XSS
Published Feb 9, 2021
·Updated
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
Affected Software
1 affected component
b2evolution b2evolution cms=6.11.6
Event History
Feb 9, 2021
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22839?
CVE-2020-22839 is considered a medium severity vulnerability due to its potential for enabling remote code execution via XSS.
2
How do I fix CVE-2020-22839?
To fix CVE-2020-22839, update your b2evolution CMS to version 6.11.7 or later.
3
What is the impact of CVE-2020-22839?
The impact of CVE-2020-22839 includes the potential for attackers to inject malicious scripts and execute them in the context of authenticated users.
4
Who is affected by CVE-2020-22839?
CVE-2020-22839 affects users of b2evolution CMS version 6.11.6.
5
What mitigation strategies are recommended for CVE-2020-22839?
Implementing input validation and output encoding can help mitigate the risk posed by CVE-2020-22839.