CVE-2021-31631: CSRF
Published Dec 6, 2021
·Updated
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Affected Software
1 affected component
b2evolution b2evolution cms=7.2.3
Event History
Dec 6, 2021
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-31631?
CVE-2021-31631 is classified as a medium severity vulnerability due to its capability to allow privilege escalation.
2
How does CVE-2021-31631 exploit the b2evolution CMS?
CVE-2021-31631 exploits b2evolution CMS through Cross-Site Request Forgery on the User login page.
3
What impact does CVE-2021-31631 have on affected systems?
CVE-2021-31631 allows attackers to escalate privileges, potentially compromising user accounts and sensitive data.
4
How do I fix CVE-2021-31631?
To fix CVE-2021-31631, update b2evolution CMS to the latest version provided by the vendor, addressing the CSRF vulnerability.
5
Which versions of b2evolution CMS are affected by CVE-2021-31631?
CVE-2021-31631 specifically affects b2evolution CMS version 7.2.3.