PT-2020-12058 · Chadha · Phpkb Standard Multi-Language

Published

2020-03-12

·

Updated

2022-08-19

·

CVE-2020-10388

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chadha PHPKB Standard Multi-Language version 9
Description The issue concerns the handling of the Referer header in article.php, allowing attackers to execute Stored (Blind) XSS by injecting arbitrary web script or HTML. This is specifically related to the admin/report-referrers.php file, with the vulnerable code located in the admin/include/functions-articles.php file.
Recommendations For version 9, consider restricting access to the admin/report-referrers.php file and the functions-articles.php module to minimize the risk of exploitation until a proper fix is applied. As a temporary workaround, disabling the handling of the Referer header in article.php may help mitigate the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-10388

Affected Products

Phpkb Standard Multi-Language