S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-18268 Scanner

CVE-2020-18268 scanner - Open Redirect vulnerability in Z-BlogPHP

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-18268
6.1
CVSS

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Z-BlogPHP is a popular open-source blogging platform used by many individuals and organizations for creating and managing content online. The platform offers a simple and user-friendly interface that makes it easy for bloggers to publish their articles, share their thoughts, and interact with their readers. With its intuitive features and customizable templates, Z-BlogPHP has become one of the most sought-after blogging platforms in the digital world.

However, despite its popularity and widespread usage, Z-BlogPHP is not immune to vulnerabilities. Recently, a critical security flaw was discovered in this platform that could expose sensitive information of its users to remote attackers. This vulnerability is identified as "CVE-2020-18268" and affects all versions of Z-BlogPHP v1.5.2 and lower.

When exploited, this vulnerability allows remote attackers to obtain sensitive information by manipulating the "redirect" parameter in the component "zb_system/cmd.php.". This means that an attacker can trick users into following a malicious link that appears to be legitimate but redirects them to a phishing site or an unsecured page. Once a user follows the link, the attacker can then gain access to their personal information, including login credentials, financial data, and other sensitive data.

At s4e.io, we strive to provide our users with the latest information on cybersecurity vulnerabilities like the one found in Z-BlogPHP. With the pro features of our platform, users can easily and quickly learn about vulnerabilities in their digital assets, allowing them to take necessary precautions to protect themselves and their data from potential threats. So, don't hesitate to subscribe to our platform and stay ahead of the game when it comes to securing your online presence.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users should take the following precautions:

  • Install the latest version of Z-BlogPHP, which contains a fix for this vulnerability.
  • Do not click on suspicious links or visit unverified websites.
  • Enable firewall protection and use an updated anti-virus program to detect and block malicious traffic.
  • Regularly backup important data and store them in secure locations.
  • Educate users about the risks of phishing attacks and advise them to be cautious while browsing the internet.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-18268 scanner - Open Redirect vulnerability in Z-BlogPHP | S4E