6.9
CVE-2025-67651
- EPSS 0.17%
- Veröffentlicht 31.07.2026 11:40:44
- Zuletzt bearbeitet 31.07.2026 20:16:45
- CVE-Watchlists
- Unerledigt
CSRF in PHP Jabbers scripts
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPHP Jabbers
≫
Produkt
Appointment Scheduler
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Bus Reservation System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Car Park Booking System
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Car Rental Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Cinema Booking System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Event Booking Calendar
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Event Ticketing System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Hotel Booking System
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Cleaning Business Software
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Equipment Rental Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Food Delivery Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Member Login Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Member Directory Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Availability Calendar
Default Statusunaffected
Version
0
Version <
6.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Event Calendar
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Newsletter Script
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Product Comparison Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Ticket Support Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
PHP Shopping Cart
Default Statusunaffected
Version
0
Version <
6.0
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Auto Classifieds Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Business Directory Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Availability Booking Calendar
Default Statusunaffected
Version
0
Version <
6.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Time Slots Booking Calendar
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Restaurant Booking System
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Shuttle Booking Software
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Meeting Room Booking System
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Rental Property Booking Calendar
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Service Booking Script
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Limo Booking Software
Default Statusunaffected
Version
0
Version <
2.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Taxi Booking Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Job Listing Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Property Listing Script
Default Statusunaffected
Version
0
Version <
4.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Travel Tours Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Vacation Rental Script
Default Statusunaffected
Version
0
Version <
5.1
Status
affected
HerstellerPHP Jabbers
≫
Produkt
Yacht Listing Script
Default Statusunaffected
Version
0
Version <
3.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cvd@cert.pl | 6.9 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://www.phpjabbers.com/
https://cert.pl/en/posts/2026/07/CVE-2025-67649/