CVE-2025-67650

Summary

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

Affected Software

VendorProductVersion RangeStatus
PHP JabbersAppointment Scheduler0 < 4.1affected
PHP JabbersBus Reservation System0 < 2.1affected
PHP JabbersCar Park Booking System0 < 4.1affected
PHP JabbersCar Rental Script0 < 4.1affected
PHP JabbersCinema Booking System0 < 2.1affected
PHP JabbersEvent Booking Calendar0 < 5.1affected
PHP JabbersEvent Ticketing System0 < 2.1affected
PHP JabbersHotel Booking System0 < 5.1affected
PHP JabbersCleaning Business Software0 < 2.1affected
PHP JabbersEquipment Rental Script0 < 2.1affected
PHP JabbersFood Delivery Script0 < 4.1affected
PHP JabbersMember Login Script0 < 4.1affected
PHP JabbersMember Directory Script0 < 2.1affected
PHP JabbersAvailability Calendar0 < 6.1affected
PHP JabbersPHP Event Calendar0 < 4.1affected
PHP JabbersPHP Newsletter Script0 < 5.1affected
PHP JabbersProduct Comparison Script0 < 2.1affected
PHP JabbersTicket Support Script0 < 4.1affected
PHP JabbersPHP Shopping Cart0 < 6.0affected
PHP JabbersAuto Classifieds Script0 < 4.1affected
PHP JabbersBusiness Directory Script0 < 4.1affected
PHP JabbersAvailability Booking Calendar0 < 6.1affected
PHP JabbersTime Slots Booking Calendar0 < 5.1affected
PHP JabbersRestaurant Booking System0 < 4.1affected
PHP JabbersShuttle Booking Software0 < 3.1affected
PHP JabbersMeeting Room Booking System0 < 2.1affected
PHP JabbersRental Property Booking Calendar0 < 3.1affected
PHP JabbersService Booking Script0 < 2.1affected
PHP JabbersLimo Booking Software0 < 2.1affected
PHP JabbersTaxi Booking Script0 < 3.1affected
PHP JabbersJob Listing Script0 < 4.1affected
PHP JabbersProperty Listing Script0 < 4.1affected
PHP JabbersTravel Tours Script0 < 3.1affected
PHP JabbersVacation Rental Script0 < 5.1affected
PHP JabbersYacht Listing Script0 < 3.1affected

Weaknesses

  • CWE-89: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References