PT-2020-12060 · Chadha+1 · Chadha Phpkb Standard Multi-Language+1

Published

2020-03-12

·

Updated

2022-08-19

·

CVE-2020-10390

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chadha PHPKB Standard Multi-Language version 9
Description The issue allows remote attackers to achieve code execution by saving the code to be executed as the wkhtmltopdf path via the admin/save-settings.php endpoint. This is made possible through an OS command injection vulnerability in the export.php file, which calls a vulnerable function from include/functions-article.php.
Recommendations For Chadha PHPKB Standard Multi-Language version 9, consider disabling the export.php function until a patch is available to prevent code execution. Restrict access to the admin/save-settings.php endpoint to minimize the risk of exploitation. Avoid using the wkhtmltopdf path in the affected settings until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-10390

Affected Products

Chadha Phpkb Standard Multi-Language
Wkhtmltopdf