CVE-2020-11579: High severity chadha software phpkb vulnerability
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11579?
CVE-2020-11579 is a vulnerability in Chadha PHPKB 9.0 Enterprise Edition that allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16 or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.
How does CVE-2020-11579 impact systems?
CVE-2020-11579 allows an attacker to disclose local files on vulnerable systems.
What software versions are affected by CVE-2020-11579?
Chadha PHPKB 9.0 Enterprise Edition is affected by CVE-2020-11579, as well as PHP versions before 7.2.16.
What is the severity of CVE-2020-11579?
CVE-2020-11579 is considered high severity with a CVSS score of 7.5.
How can CVE-2020-11579 be mitigated?
To mitigate CVE-2020-11579, update PHP to version 7.2.16 or later and disable the MySQL ALLOW LOCAL DATA INFILE option if not required.