admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject untrusted input inside CSV files via the POST parameter data.
- https://antoniocannito.it/phpkb1#csv-injection-cve-2020-10460
No PoCs found on GitHub currently.