Description
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Security Bypass (3.8.0 - 3.9.3)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1734)
Oracle Database Server CVE-2010-0860 Vulnerability (CVE-2010-0860)
b2evolution URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-22840)