PT-2020-12058 · Chadha · Phpkb Standard Multi-Language
Published
2020-03-12
·
Updated
2022-08-19
·
CVE-2020-10388
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chadha PHPKB Standard Multi-Language version 9
Description
The issue concerns the handling of the Referer header in article.php, allowing attackers to execute Stored (Blind) XSS by injecting arbitrary web script or HTML. This is specifically related to the admin/report-referrers.php file, with the vulnerable code located in the admin/include/functions-articles.php file.
Recommendations
For version 9, consider restricting access to the admin/report-referrers.php file and the functions-articles.php module to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, disabling the handling of the Referer header in article.php may help mitigate the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpkb Standard Multi-Language