CVE-2020-10470: XSS
Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-10470.
What is the title of the vulnerability?
The title of the vulnerability is 'Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.'
How does the vulnerability occur?
The vulnerability occurs when an attacker is able to manipulate the GET parameter 'sort' and inject malicious web script or HTML.
What is the severity of CVE-2020-10470?
The severity of CVE-2020-10470 is medium with a CVSS score of 4.8.
How can I fix the vulnerability?
To fix the vulnerability, it is recommended to update to the latest version of Chadha PHPKB Standard Multi-Language (9.0 or higher) that includes a patch to mitigate this vulnerability.