8.6
CVE-2025-67650
- EPSS 0.28%
- Veröffentlicht 31.07.2026 11:40:40
- Zuletzt bearbeitet 31.07.2026 20:16:45
- CVE-Watchlists
- Unerledigt
Authenticated SQL Injection in PHP Jabbers scripts
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Jabbers
≫
Produkt
Appointment Scheduler
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Bus Reservation System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Car Park Booking System
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Car Rental Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Cinema Booking System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Event Booking Calendar
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Event Ticketing System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Hotel Booking System
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Cleaning Business Software
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Equipment Rental Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Food Delivery Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Member Login Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Member Directory Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Availability Calendar
Default Statusunaffected
Version
0
Version <
6.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Event Calendar
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Newsletter Script
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Product Comparison Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Ticket Support Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Shopping Cart
Default Statusunaffected
Version
0
Version <
6.0
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Auto Classifieds Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Business Directory Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Availability Booking Calendar
Default Statusunaffected
Version
0
Version <
6.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Time Slots Booking Calendar
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Restaurant Booking System
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Shuttle Booking Software
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Meeting Room Booking System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Rental Property Booking Calendar
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Service Booking Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Limo Booking Software
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Taxi Booking Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Job Listing Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Property Listing Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Travel Tours Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Vacation Rental Script
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Yacht Listing Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.202 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cvd@cert.pl | 8.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
https://www.phpjabbers.com/
https://cert.pl/en/posts/2026/07/CVE-2025-67649/