The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php, via the GET parameter cmt.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10461
Reference (s):
- http://antoniocannito.it/?p=137#bxss2
- https://antoniocannito.it/phpkb1#blind-cross-site-scripting-2-cve-2020-10461

