Description
b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. Attackers can craft a malicious HTML form to submit unauthorized changes to user profiles by tricking victims into loading a specially crafted webpage.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Alperen Ergel (@alpernae)
References
www.exploit-db.com/exploits/50081 (ExploitDB-50081)
b2evolution.net/ (Official Vendor Homepage)
b2evolution.net/downloads/ (Software Download Page)
github.com/b2evolution/b2evolution (B2Evolution GitHub Repository)
www.vulncheck.com/...details-cross-site-request-forgery-csrf (VulnCheck Advisory: b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF))