First published: Thu Mar 12 2020(Updated: )
Reflected XSS in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chadhaajay Phpkb | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10474 is a vulnerability in Chadha PHPKB Standard Multi-Language 9 that allows attackers to inject arbitrary web script or HTML via the GET parameter sort in the admin/manage-comments.php file.
The severity of CVE-2020-10474 is medium, with a severity score of 4.8.
CVE-2020-10474 affects Chadha PHPKB Standard Multi-Language 9 by allowing attackers to inject arbitrary web script or HTML when the GET parameter sort is used in the admin/manage-comments.php file.
To fix CVE-2020-10474, update Chadha PHPKB Standard Multi-Language to version 9.0 or higher, as this vulnerability has been patched in the latest version.
For more information about CVE-2020-10474, you can refer to the following references: http://antoniocannito.it/?p=342#xss13 and https://antoniocannito.it/phpkb2#reflected-cross-site-scripting-when-deleting-a-comment-cve-2020-10474.