CVE-2020-22841 EXPLOIT
4.8
MEDIUM · CVSS 3.1 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
Scoring
| CVSS | 4.8 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 3.54% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-02-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| b2evolution | b2evolution |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | b2evolution 6.11.6 - 'plugin name' Stored XSS | 2021-02-10 |
References
- http://packetstormsecurity.com/files/161363/b2evolution-CMS-6.11.6-Cross-Site-Scripting.html
- https://github.com/b2evolution/b2evolution/issues/102
- https://www.exploit-db.com/exploits/49551
- http://packetstormsecurity.com/files/161363/b2evolution-CMS-6.11.6-Cross-Site-Scripting.html
- https://github.com/b2evolution/b2evolution/issues/102
- https://www.exploit-db.com/exploits/49551
→ the Explorer · watch your stack · NVD