Description
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.
Remediation
References
Related Vulnerabilities
MySQL Improper Input Validation Vulnerability (CVE-2012-5614)
WordPress Plugin Count per Day 'notes.php' Cross-Site Scripting (3.2.3)
Oracle Database Server CVE-2014-6514 Vulnerability (CVE-2014-6514)
Apache Tomcat Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5351)
CakePHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4399)