CVE-2020-10389: Code Injection
Published Mar 12, 2020
·Updated
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.
Affected Software
1 affected component
Chadhaajay Phpkb=9.0
Event History
Mar 12, 2020
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10389?
CVE-2020-10389 is classified as a high-severity vulnerability that allows remote code execution.
2
How do I fix CVE-2020-10389?
To fix CVE-2020-10389, immediately update to the latest version of Chadha PHPKB that addresses this vulnerability.
3
Who is affected by CVE-2020-10389?
CVE-2020-10389 affects users of Chadha PHPKB Standard Multi-Language version 9.0.
4
What type of vulnerability is CVE-2020-10389?
CVE-2020-10389 is a remote code execution vulnerability due to unsafe handling of POST parameters.
5
Can CVE-2020-10389 be exploited remotely?
Yes, CVE-2020-10389 can be exploited remotely by injecting PHP code through POST requests.