← Back

B2evolution Cms

b2evolution_cms

Vendor: B2evolution • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1B2evolution
1B2evolution Cms
Nov 21, 2024
Jan 3, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a fea...Show more
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."Show less
1B2evolution
1B2evolution Cms
Nov 21, 2024
Dec 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
1B2evolution
1B2evolution Cms
Nov 21, 2024
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
1B2evolution
1B2evolution Cms
Nov 21, 2024
Feb 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.