Reflected XSS in admin/edit-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter p.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10462
Reference (s):
- http://antoniocannito.it/?p=342#xss1
- https://antoniocannito.it/phpkb2#reflected-cross-site-scripting-when-editing-a-custom-field-cve-2020-10462

