CVE-2021-47800: b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. Attackers can craft a malicious HTML form to submit unauthorized changes to user profiles by tricking victims into loading a specially crafted webpage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47800?
CVE-2021-47800 has a medium severity rating due to its potential to allow unauthorized changes to admin account details.
How do I fix CVE-2021-47800?
To fix CVE-2021-47800, ensure you upgrade to the latest version of b2evolution that has the CSRF vulnerability patched.
Who is affected by CVE-2021-47800?
CVE-2021-47800 affects users of b2evolution version 7.2.2 who have not implemented appropriate security measures.
What type of vulnerability is CVE-2021-47800?
CVE-2021-47800 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
What can attackers do with CVE-2021-47800?
Attackers can exploit CVE-2021-47800 to modify admin account details without authentication.