CVE-2025-67651

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.

This issue was fixed in the versions specified in the affected products list.

Affected Software

VendorProductVersion RangeStatus
PHP JabbersAppointment Scheduler0 < 4.1affected
PHP JabbersBus Reservation System0 < 2.1affected
PHP JabbersCar Park Booking System0 < 4.1affected
PHP JabbersCar Rental Script0 < 4.1affected
PHP JabbersCinema Booking System0 < 2.1affected
PHP JabbersEvent Booking Calendar0 < 5.1affected
PHP JabbersEvent Ticketing System0 < 2.1affected
PHP JabbersHotel Booking System0 < 5.1affected
PHP JabbersCleaning Business Software0 < 2.1affected
PHP JabbersEquipment Rental Script0 < 2.1affected
PHP JabbersFood Delivery Script0 < 4.1affected
PHP JabbersMember Login Script0 < 4.1affected
PHP JabbersMember Directory Script0 < 2.1affected
PHP JabbersAvailability Calendar0 < 6.1affected
PHP JabbersPHP Event Calendar0 < 4.1affected
PHP JabbersPHP Newsletter Script0 < 5.1affected
PHP JabbersProduct Comparison Script0 < 2.1affected
PHP JabbersTicket Support Script0 < 4.1affected
PHP JabbersPHP Shopping Cart0 < 6.0affected
PHP JabbersAuto Classifieds Script0 < 4.1affected
PHP JabbersBusiness Directory Script0 < 4.1affected
PHP JabbersAvailability Booking Calendar0 < 6.1affected
PHP JabbersTime Slots Booking Calendar0 < 5.1affected
PHP JabbersRestaurant Booking System0 < 4.1affected
PHP JabbersShuttle Booking Software0 < 3.1affected
PHP JabbersMeeting Room Booking System0 < 2.1affected
PHP JabbersRental Property Booking Calendar0 < 3.1affected
PHP JabbersService Booking Script0 < 2.1affected
PHP JabbersLimo Booking Software0 < 2.1affected
PHP JabbersTaxi Booking Script0 < 3.1affected
PHP JabbersJob Listing Script0 < 4.1affected
PHP JabbersProperty Listing Script0 < 4.1affected
PHP JabbersTravel Tours Script0 < 3.1affected
PHP JabbersVacation Rental Script0 < 5.1affected
PHP JabbersYacht Listing Script0 < 3.1affected

Weaknesses

  • CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References