PT-2020-12099 · Chadha · Chadha Phpkb Standard Multi-Language

CVE-2020-10429

·

Published

2020-03-12

·

Updated

2022-08-19

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Chadha PHPKB Standard Multi-Language version 9
Description The issue concerns the handling of URIs in admin/header.php, which allows for Reflected XSS attacks. This can be exploited by injecting arbitrary web script or HTML in admin/manage-settings.php through the addition of a question mark (?) followed by the payload.
Recommendations For version 9, consider restricting access to the admin/manage-settings.php endpoint until a proper fix is applied, and ensure that all user input is properly sanitized to prevent the injection of malicious scripts. As a temporary workaround, avoid using the admin/header.php file to handle URIs, or apply input validation to prevent the addition of malicious payloads.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10429

Affected Products

Chadha Phpkb Standard Multi-Language