CVE-2020-10388: XSS
Published Mar 12, 2020
·Updated
The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php (vulnerable file admin/include/functions-articles.php).
Affected Software
1 affected component
Chadhaajay Phpkb=9.0
Event History
Mar 12, 2020
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10388?
The severity of CVE-2020-10388 is classified as a medium risk due to the potential for stored XSS attacks.
2
How do I fix CVE-2020-10388?
To fix CVE-2020-10388, you should validate and sanitize user input in the Referer header processing.
3
What systems are affected by CVE-2020-10388?
CVE-2020-10388 affects Chadha PHPKB Standard Multi-Language version 9.0.
4
What type of vulnerability is CVE-2020-10388?
CVE-2020-10388 is a stored (blind) cross-site scripting (XSS) vulnerability.
5
What can attackers achieve with CVE-2020-10388?
Attackers can execute arbitrary web scripts or HTML code by exploiting the stored XSS vulnerability in CVE-2020-10388.