CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.
CVE
CVE-2020-10461
Severity
MEDIUM
CVSS
6.1
EPSS
0.74%
Original NVD Description
The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/manage-comments.php, via the GET parameter cmt.
Related CVEs
Other vulnerabilities affecting the same vendor(s)