Description
b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Support Plus Responsive Ticket System Privilege Escalation (7.1.4)
WordPress Plugin Hostel Cross-Site Scripting (1.1.3)
WordPress Plugin CigiCigi Post Guest Cross-Site Scripting (1.0.5)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-9591)
WordPress Plugin Rotating Testimonial Cross-Site Scripting (1.1)