CVE-2020-10456: XSS
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/trash-box.php by adding a question mark (?) followed by the payload.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10456?
CVE-2020-10456 is a vulnerability in Chadha PHPKB Standard Multi-Language 9 that allows for Reflected XSS attacks.
How does CVE-2020-10456 work?
CVE-2020-10456 works by injecting arbitrary web script or HTML in admin/trash-box.php by adding a question mark (?) followed by the payload in the URI.
What is the severity of CVE-2020-10456?
CVE-2020-10456 has a severity rating of medium with a CVSS score of 4.8.
How can I fix CVE-2020-10456?
To fix CVE-2020-10456, update Chadha PHPKB Standard Multi-Language to the latest version available.
Where can I find more information about CVE-2020-10456?
You can find more information about CVE-2020-10456 at the following references: http://antoniocannito.it/?p=137#uxss and https://antoniocannito.it/phpkb1#reflected-cross-site-scripting-in-every-admin-page-cve-block-going-from-cve-2020-10391-to-cve-2020-10456.