Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the “redirect” parameter in the component “zb_system/cmd.php.”
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18268
Reference (s):
- https://github.com/zblogcn/zblogphp/issues/209
- https://github.com/zblogcn/zblogphp/issues/216