Back to Database
Status published
High
CVE-2021-31631
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request...
Vulnerability Description
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-31631
Credits & Attribution
No credits recorded in the NVD database.
More from b2evolution
View All →CVE-2022-44036
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload...
Unknown
0
CVE-2022-30935
An authorization bypass in b2evolution allows remote, unauthenticated attackers to...
Unknown
0
CVE-2021-31632
b2evolution CMS v7.2.3 was discovered to contain a SQL injection...
Critical
9.8
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows...
High
8.8
CVE-2020-22841
Stored XSS in b2evolution CMS version 6.11.6 and prior allows...
Medium
4.8
Affected Vendor
b2evolution
View all reports →Affected Software
b2evolution cms
Vulnerable Versions:
7.2.3
Timeline
Official Publish:
December 6th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.