CVE-2020-22841

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/02/2021
Last modified:
17/02/2021

Description

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:b2evolution:b2evolution:*:*:*:*:*:*:*:* 6.11.6 (excluding)