.. / CVE-2020-22840

Exploit for b2evolution CMS <6.11.6 - Open Redirect (CVE-2020-22840)

Description:

b2evolution CMS before 6.11.6 contains an open redirect vulnerability via the redirect_to parameter in email_passthrough.php. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2020-22840.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-22840.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://github.com/b2evolution/b2evolution/issues/102
http://packetstormsecurity.com/files/161362/b2evolution-CMS-6.11.6-Open-Redirection.html
https://nvd.nist.gov/vuln/detail/CVE-2020-22840
https://www.exploit-db.com/exploits/49554