Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Chadhaajay Subscribe
Total 119 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-10487 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
CVE-2020-10489 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.
CVE-2020-10488 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.
CVE-2020-10490 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.
CVE-2020-10493 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.
CVE-2020-10499 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.
CVE-2020-10500 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.
CVE-2020-10494 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.
CVE-2020-10495 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.
CVE-2020-10496 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.
CVE-2020-10498 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 6.5 MEDIUM
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
CVE-2020-10501 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 6.5 MEDIUM
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
CVE-2020-10491 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted request.
CVE-2020-10503 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.
CVE-2020-10502 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.
CVE-2020-10492 1 Chadhaajay 1 Phpkb 2022-09-02 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.
CVE-2020-10504 1 Chadhaajay 1 Phpkb 2022-08-19 4.3 MEDIUM 4.3 MEDIUM
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
CVE-2020-10387 1 Chadhaajay 1 Phpkb 2022-08-19 4.0 MEDIUM 4.9 MEDIUM
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.
CVE-2020-10391 1 Chadhaajay 1 Phpkb 2022-08-19 3.5 LOW 4.8 MEDIUM
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-article.php by adding a question mark (?) followed by the payload.
CVE-2020-10388 1 Chadhaajay 1 Phpkb 2022-08-19 3.5 LOW 5.4 MEDIUM
The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-referrers.php (vulnerable file admin/include/functions-articles.php).