← Back

Chadhaajay

chadhaajay

119 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Phpkb
phpkb

CVEs (119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chadhaajay
1Phpkb
Nov 21, 2024
Sep 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP befor...Show more
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.Show less
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
1Chadhaajay
1Phpkb
Nov 21, 2024
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.