Reflected XSS in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10475
Reference (s):
- http://antoniocannito.it/?p=342#xss14
- https://antoniocannito.it/phpkb2#reflected-cross-site-scripting-when-deleting-a-ticket-cve-2020-10475