First published: Tue Feb 09 2021(Updated: )
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Evolution | <6.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22840 is rated as medium severity due to its potential to lead to open redirect attacks.
To fix CVE-2020-22840, upgrade b2evolution CMS to version 6.11.6 or later.
The impact of CVE-2020-22840 allows attackers to redirect users to malicious websites, potentially leading to phishing or other malicious activities.
CVE-2020-22840 affects b2evolution CMS versions prior to 6.11.6.
Yes, CVE-2020-22840 can be exploited without authentication, making it easier for attackers to leverage the vulnerability.