CVEs Blog | G5 Cyber Security

CVE-2020-10447 – The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-failed-login.php by adding a question mark (?) followed by the payload.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10447

Reference (s):

Exit mobile version