Executive brief
b2evolution, a content management system used for blogs and community websites, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages. By posting specially crafted links in forums, an attacker can execute code in the browsers of other users who view the content. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in b2evolution versions 6.7.5 and earlier due to improper neutralization of input in the 'autolink' function (specifically within the 'make_clickable' utility). An unauthenticated remote attacker can exploit this by posting content, such as a forum message, containing a malformed URL with embedded JavaScript event handlers (e.g., onmouseover). When other users view the affected page, the malicious script executes in their browser context. The vulnerability was addressed by updating the autolink logic to properly terminate URL parsing before reaching injected attributes. A fix is available in the project's GitHub repository (commit 9a4ab85).
Affected products
- b2evolution.net b2evolution 6.7.5 and earlier
Timeline
- 2016-08-12: disclosed: Vendor notified by researcher Chen Ruiqi
- 2016-09-12: other: Public CVE request on oss-security mailing list
- 2017-01-18: advisory: NVD publication date