vendor:
b2evolution
by:
@nu11secur1ty
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: b2evolution
Affected Version From: 7-2-2
Affected Version To: 7-2-2
Patch Exists: YES
Related CWE: CVE-2021-28242
CPE: a:b2evolution:b2evolution:7.2.2
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=159656, https://www.infosecmatter.com/nessus-plugin-library/?id=159657, https://www.infosecmatter.com/nessus-plugin-library/?id=27514, https://www.infosecmatter.com/nessus-plugin-library/?id=67589, https://www.infosecmatter.com/nessus-plugin-library/?id=27071, https://www.infosecmatter.com/nessus-plugin-library/?id=28139
Platforms Tested: None
2021
b2evolution 7-2-2 – ‘cf_name’ SQL Injection
A vulnerability in b2evolution 7-2-2 allows an attacker to inject SQL commands into the 'cf_name' parameter and obtain sensitive database information from the 'evo_users' and 'evo_blogs' tables.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.