CVE-2020-18268 describes an Open Redirect vulnerability in Z-BlogPHP versions 1.5.2 and earlier, specifically within the "zb_system/cmd.php" component, allowing attackers to manipulate the "redirect" parameter. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low complexity, requiring user interaction to potentially lead to information disclosure and limited integrity impact. While there is no evidence of active exploitation or KEV listing, a Nuclei template exists, indicating public awareness of exploit development, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.2CPE matchmatch criteria | cpe:2.3:a:zblogcn:z-blogphp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.