CVE-2025-67651
- EPSS 0.17%
- Veröffentlicht 31.07.2026 11:40:44
- Zuletzt bearbeitet 31.07.2026 20:16:45
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user...
CVE-2025-67650
- EPSS 0.28%
- Veröffentlicht 31.07.2026 11:40:40
- Zuletzt bearbeitet 31.07.2026 20:16:45
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL I...
CVE-2025-67649
- EPSS 0.27%
- Veröffentlicht 31.07.2026 11:40:25
- Zuletzt bearbeitet 31.07.2026 20:16:45
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection att...
CVE-2023-48837
- EPSS 0.47%
- Veröffentlicht 07.12.2023 07:15:12
- Zuletzt bearbeitet 21.11.2024 08:32:32
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
CVE-2023-48834
- EPSS 1.05%
- Veröffentlicht 07.12.2023 07:15:11
- Zuletzt bearbeitet 28.05.2025 16:15:31
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
CVE-2023-48835
- EPSS 1.2%
- Veröffentlicht 07.12.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:32:31
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
CVE-2023-48836
- EPSS 0.47%
- Veröffentlicht 07.12.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 08:32:31
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
CVE-2023-40764
- EPSS 0.75%
- Veröffentlicht 28.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:06
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid use...
CVE-2023-40754
- EPSS 0.72%
- Veröffentlicht 28.08.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:20:04
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.