PoC Index

CVE-2020-22841

MEDIUM 4.8EPSS 3.5%

Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
3.54% chance of exploitation in the next 30 days, 88th percentile
Published
2021-02-09
Updated
2024-08-04

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related