CVE-2020-22840: Medium severity evolution vulnerability
Published Feb 9, 2021
·Updated
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirectto parameter in emailpassthrough.php.
Affected Software
1 affected component
b2evolution b2evolution<6.11.6
Event History
Feb 9, 2021
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22840?
CVE-2020-22840 is rated as medium severity due to its potential to lead to open redirect attacks.
2
How do I fix CVE-2020-22840?
To fix CVE-2020-22840, upgrade b2evolution CMS to version 6.11.6 or later.
3
What is the impact of CVE-2020-22840?
The impact of CVE-2020-22840 allows attackers to redirect users to malicious websites, potentially leading to phishing or other malicious activities.
4
Which versions of b2evolution are affected by CVE-2020-22840?
CVE-2020-22840 affects b2evolution CMS versions prior to 6.11.6.
5
Can CVE-2020-22840 be exploited without authentication?
Yes, CVE-2020-22840 can be exploited without authentication, making it easier for attackers to leverage the vulnerability.