First published: Mon Dec 06 2021(Updated: )
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
B2evolution | =7.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31631 is classified as a medium severity vulnerability due to its capability to allow privilege escalation.
CVE-2021-31631 exploits b2evolution CMS through Cross-Site Request Forgery on the User login page.
CVE-2021-31631 allows attackers to escalate privileges, potentially compromising user accounts and sensitive data.
To fix CVE-2021-31631, update b2evolution CMS to the latest version provided by the vendor, addressing the CSRF vulnerability.
CVE-2021-31631 specifically affects b2evolution CMS version 7.2.3.