vendor:
PHPKB Standard Multi-Language 9
by:
Antonio Cannito
4.9
CVSS
MEDIUM
Authenticated Directory Traversal
22
CWE
Product Name: PHPKB Standard Multi-Language 9
Affected Version From: Multi-Language v9
Affected Version To: Multi-Language v9
Patch Exists: YES
Related CWE: CVE-2020-10387
CPE: a:chadha_software_solutions:phpkb_standard_multi-language_9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 8.1 / PHP 7.4.3
2020
PHPKB Multi-Language 9 – Authenticated Directory Traversal
A vulnerability in Chadha PHPKB Standard Multi-Language 9 allows an authenticated attacker to download arbitrary files from the server. This is due to a lack of proper input validation in the 'file' parameter of the 'admin/download.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malicious 'file' parameter.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Chadha PHPKB Standard Multi-Language 9.