{"id":"CVE-2020-22839","details":"Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.","modified":"2026-04-11T20:42:02.998557Z","published":"2021-02-09T20:15:12.940Z","references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/161363/b2evolution-CMS-6.11.6-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"https://sohambakore.medium.com/b2evolution-cms-reflected-xss-in-tab-type-parameter-in-evoadm-php-38886216cdd3"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/49555"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/b2evolution/b2evolution","events":[{"introduced":"0"},{"last_affected":"c4c3c02c00b937f312676003d820ad72f4813631"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.11.6"}],"cpe":"cpe:2.3:a:b2evolution:b2evolution_cms:6.11.6:*:*:*:*:*:*:*","source":"CPE_FIELD"}}],"versions":["6-9-4","6-9-5","6.0.0-alpha","6.0.0-alpha.1","6.1.2-alpha","6.10.2","6.10.3","6.10.4","6.10.5","6.10.6","6.10.7","6.10.8","6.11.4","6.11.5","6.11.6","6.4.2-beta","6.4.3-beta","6.4.4-beta","6.5.0","6.6.0","6.6.1","6.6.4","6.6.5","6.6.6","6.6.7","6.6.8","6.7.5","6.7.6","6.7.7","6.8.10","6.8.3","6.8.4","6.8.5","6.8.6","6.8.7","6.8.8","6.8.9","6.9.3","6.9.4","6.9.5","6.9.7","v5.2.0-stable"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-22839.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}