First published: Thu Mar 12 2020(Updated: )
Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chadhaajay Phpkb | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-10470.
The title of the vulnerability is 'Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.'
The vulnerability occurs when an attacker is able to manipulate the GET parameter 'sort' and inject malicious web script or HTML.
The severity of CVE-2020-10470 is medium with a CVSS score of 4.8.
To fix the vulnerability, it is recommended to update to the latest version of Chadha PHPKB Standard Multi-Language (9.0 or higher) that includes a patch to mitigate this vulnerability.