ZeroHour

CVE-2017-1000423

CVSS 3.0
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.

Vendors
b2evolution
Products
b2evolution
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.