CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10504
Reference (s):
- http://antoniocannito.it/?p=343#csrf27
- https://antoniocannito.it/phpkb3#cross-site-request-forgery-when-editing-a-comment-cve-2020-10504

