b2evolution Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-22841 - Vulnerability Database
b2evolution Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-22841
Medium
Reference:
CVE-2020-22841
Title:
b2evolution Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.