CVE-2020-22840

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
09/02/2021
Last modified:
17/02/2021

Description

Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:b2evolution:b2evolution:*:*:*:*:*:*:*:* 6.11.6 (excluding)