CVE-2025-67649 PUBLISHED

Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script

Assigner: CERT-PL
Reserved: 09.12.2025 Published: 31.07.2026 Updated: 31.07.2026

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.

This issue was fixed in version 4.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor PHP Jabbers
Product Car Rental Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)

Credits

  • Kamil Szczurowski finder
  • Robert Kruczek finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection