CVE-2020-10460: Chadhaajay Phpkb

Medium severity, CVSS 4.9. EPSS: 1.1% chance of exploitation in the next 30 days.

admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.

Affected products

Published 2020-03-12. Last modified 2026-06-17.