CVE-2020-10390: Command Injection
Published Mar 12, 2020
·Updated
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be executed as the wkhtmltopdf path via admin/save-settings.php.
Affected Software
1 affected component
Chadhaajay Phpkb=9.0
Event History
Mar 12, 2020
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10390?
CVE-2020-10390 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2020-10390?
To fix CVE-2020-10390, update to the latest version of Chadha PHPKB that addresses this vulnerability.
3
What systems are affected by CVE-2020-10390?
CVE-2020-10390 affects Chadha PHPKB Standard Multi-Language version 9.0.
4
Can CVE-2020-10390 be exploited remotely?
Yes, CVE-2020-10390 can be exploited remotely by attackers.
5
What type of attack can CVE-2020-10390 enable?
CVE-2020-10390 can enable an OS command injection attack, potentially leading to code execution.