PT-2020-12072 · Chadha · Chadha Phpkb Standard Multi-Language
Published
2020-03-12
·
Updated
2022-08-19
·
CVE-2020-10402
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Chadha PHPKB Standard Multi-Language version 9
Description
The issue concerns the handling of URIs in admin/header.php, which allows for Reflected XSS attacks. This can be exploited in admin/edit-category.php by adding a question mark (?) followed by the payload, enabling the injection of arbitrary web script or HTML.
Recommendations
For Chadha PHPKB Standard Multi-Language version 9, consider restricting access to the admin/edit-category.php page until a proper fix is applied, and ensure that all user input is properly sanitized to prevent XSS attacks. As a temporary workaround, consider validating and encoding all URI parameters to prevent malicious injections.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chadha Phpkb Standard Multi-Language