Home/Product/chadhaajay phpkb
Product

chadhaajay phpkb

120 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-11579
all versions
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) a
7.5HIGH
CVE-2020-10504
all versions
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a
4.3MEDIUM
CVE-2020-10503
all versions
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the
4.3MEDIUM
CVE-2020-10502
all versions
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id,
4.3MEDIUM
CVE-2020-10501
all versions
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id
6.5MEDIUM
CVE-2020-10500
all versions
CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, vi
4.3MEDIUM
CVE-2020-10499
all versions
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via
4.3MEDIUM
CVE-2020-10498
all versions
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a
6.5MEDIUM
CVE-2020-10497
all versions
CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted
6.5MEDIUM
CVE-2020-10496
all versions
CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a
4.3MEDIUM
CVE-2020-10495
all versions
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the
4.3MEDIUM
CVE-2020-10494
all versions
CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a
4.3MEDIUM
CVE-2020-10493
all versions
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id,
4.3MEDIUM
CVE-2020-10492
all versions
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a
4.3MEDIUM
CVE-2020-10491
all versions
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted
4.3MEDIUM
CVE-2020-10490
all versions
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a craft
4.3MEDIUM
CVE-2020-10489
all versions
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted reque
4.3MEDIUM
CVE-2020-10488
all versions
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted re
4.3MEDIUM
CVE-2020-10487
all versions
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a craft
4.3MEDIUM
CVE-2020-10486
all versions
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted req
4.3MEDIUM
CVE-2020-10485
all versions
CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted re
4.3MEDIUM
CVE-2020-10484
all versions
CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted requ
4.3MEDIUM
CVE-2020-10483
all versions
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a craft
4.3MEDIUM
CVE-2020-10482
all versions
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a craf
4.3MEDIUM
CVE-2020-10481
all versions
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted
4.3MEDIUM
CVE-2020-10480
all versions
CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted requ
4.3MEDIUM
CVE-2020-10479
all versions
CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted requ
4.3MEDIUM
CVE-2020-10478
all versions
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potent
8.8HIGH
CVE-2020-10477
all versions
Reflected XSS in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script o
4.8MEDIUM
CVE-2020-10476
all versions
Reflected XSS in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web scri
4.8MEDIUM
CVE-2020-10475
all versions
Reflected XSS in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web scrip
4.8MEDIUM
CVE-2020-10474
all versions
Reflected XSS in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web scri
4.8MEDIUM
CVE-2020-10473
all versions
Reflected XSS in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web sc
4.8MEDIUM
CVE-2020-10472
all versions
Reflected XSS in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web scr
4.8MEDIUM
CVE-2020-10471
all versions
Reflected XSS in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web scri
4.8MEDIUM
CVE-2020-10470
all versions
Reflected XSS in admin/manage-fields.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10469
all versions
Reflected XSS in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web s
4.8MEDIUM
CVE-2020-10468
all versions
Reflected XSS in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or
4.8MEDIUM
CVE-2020-10467
all versions
Reflected XSS in admin/edit-comment.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10466
all versions
Reflected XSS in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10465
all versions
Reflected XSS in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10464
all versions
Reflected XSS in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10463
all versions
Reflected XSS in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script
4.8MEDIUM
CVE-2020-10462
all versions
Reflected XSS in admin/edit-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or
4.8MEDIUM
CVE-2020-10461
all versions
The way comments in article.php (vulnerable function in include/functions-article.php) are handled in Chadha PHPKB Standard Multi-
6.1MEDIUM
CVE-2020-10460
all versions
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject
4.9MEDIUM
CVE-2020-10459
all versions
Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PH
2.7LOW
CVE-2020-10458
all versions
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder
6.5MEDIUM
CVE-2020-10457
all versions
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any fi
2.7LOW
CVE-2020-10456
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10455
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10454
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10453
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10452
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10451
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10450
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10449
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10448
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10447
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10446
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10445
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10444
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10443
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10442
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10441
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10440
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10439
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10438
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10437
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10436
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10435
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10434
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10433
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10432
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10431
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10430
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10429
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10428
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10427
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10426
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10425
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10424
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10423
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10422
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10421
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10420
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10419
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10418
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10417
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10416
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10415
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10414
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10413
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10412
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10411
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10410
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10409
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10408
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10407
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10406
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10405
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10404
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10403
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10402
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10401
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10400
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10399
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10398
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10397
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10396
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10395
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10394
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10393
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10392
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10391
all versions
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary w
4.8MEDIUM
CVE-2020-10390
all versions
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-
7.2HIGH
CVE-2020-10389
all versions
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting P
7.2HIGH
CVE-2020-10388
all versions
The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored
5.4MEDIUM
CVE-2020-10387
all versions
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the
4.9MEDIUM
CVE-2020-10386
all versions
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by
7.2HIGH
threatengine.sh