CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows malicious users to close any ticket, given the id, via a crafted request.
chadhaajay phpkb 9.0