CVE-2020-10460
MEDIUMChadha PHPKB Standard Multi-Language 9 - Code Injection
Title source: llmDescription
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
http://antoniocannito.it/?p=137#csvinj
Exploit, Third Party Advisory x_refsource_misc
https://antoniocannito.it/phpkb1#csv-injection-cve-2020-10460
Scores
CVSS v3
4.9
EPSS
0.0108
EPSS Percentile
60.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-1236
Status
published
Products (1)
chadhaajay/phpkb
9.0
Published
Mar 12, 2020
Tracked Since
Feb 18, 2026