CVE-2020-11579 is a high-severity vulnerability affecting Chadha PHPKB 9.0 Enterprise Edition, specifically within its installer/test-connection.php component. This flaw allows an unauthenticated remote attacker to disclose local files on vulnerable hosts, particularly those running PHP versions older than 7.2.16 or with MySQL's ALLOW LOCAL DATA INFILE option enabled. The vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and no user interaction required, leading to high confidentiality impact. Its FAUCET Risk Score is 95/100, and its EPSS score is higher than 97% of all CVEs, suggesting a significant likelihood of exploitation. While there are no public exploits in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered community attention with one mention and one media article discussing its potential for exfiltration through MySQL, indicating awareness and potential for future exploitation. It is not listed in CISA's KEV catalog and is currently inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:chadhaajay:phpkb:9.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.