Vulnerability Details CVE-2020-11579
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on hosts running PHP before 7.2.16, or on hosts where the MySQL ALLOW LOCAL DATA INFILE option is enabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.152
EPSS Ranking 94.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0