CVEFinder.io

CVE-2020-10388

🔶 medium
🔍 Scan for this CVE
Summary

The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php (vulnerable file admin/include/functions-articles.php).

CVSS Score
5.4
Medium
EPSS Score
0.3
Exploit Probability
Published Date
2020-03-12
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 22.9% of all 325,576 vulnerabilities in our database.

#251,158
Below average severity
Severity Percentile
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

http://antoniocannito.it/?p=137#bxss1
Exploit Third Party Advisory

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2020-11579 ⚠️ high 7.5 36.7 An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation ... 2020-09-03
CVE-2020-10386 ⚠️ high 7.2 18.7 admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Exe... 2020-03-12
CVE-2020-10387 🔶 medium 4.9 12.8 Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files... 2020-03-12
CVE-2020-10389 ⚠️ high 7.2 9.0 admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by i... 2020-03-12
CVE-2020-10390 ⚠️ high 7.2 4.7 OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Stand... 2020-03-12
CVE-2020-10391 🔶 medium 4.8 0.3 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting a... 2020-03-12
These CVEs affect the same products