CVE-2025-67650 PUBLISHED

Authenticated SQL Injection in PHP Jabbers scripts

Assigner: CERT-PL
Reserved: 09.12.2025 Published: 31.07.2026 Updated: 31.07.2026

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor PHP Jabbers
Product Appointment Scheduler
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Bus Reservation System
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Car Park Booking System
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Car Rental Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Cinema Booking System
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Event Booking Calendar
Versions Default: unaffected
  • affected from 0 to 5.1 (excl.)
Vendor PHP Jabbers
Product Event Ticketing System
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Hotel Booking System
Versions Default: unaffected
  • affected from 0 to 5.1 (excl.)
Vendor PHP Jabbers
Product Cleaning Business Software
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Equipment Rental Script
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Food Delivery Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Member Login Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Member Directory Script
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Availability Calendar
Versions Default: unaffected
  • affected from 0 to 6.1 (excl.)
Vendor PHP Jabbers
Product PHP Event Calendar
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product PHP Newsletter Script
Versions Default: unaffected
  • affected from 0 to 5.1 (excl.)
Vendor PHP Jabbers
Product Product Comparison Script
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Ticket Support Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product PHP Shopping Cart
Versions Default: unaffected
  • affected from 0 to 6.0 (excl.)
Vendor PHP Jabbers
Product Auto Classifieds Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Business Directory Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Availability Booking Calendar
Versions Default: unaffected
  • affected from 0 to 6.1 (excl.)
Vendor PHP Jabbers
Product Time Slots Booking Calendar
Versions Default: unaffected
  • affected from 0 to 5.1 (excl.)
Vendor PHP Jabbers
Product Restaurant Booking System
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Shuttle Booking Software
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)
Vendor PHP Jabbers
Product Meeting Room Booking System
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Rental Property Booking Calendar
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)
Vendor PHP Jabbers
Product Service Booking Script
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Limo Booking Software
Versions Default: unaffected
  • affected from 0 to 2.1 (excl.)
Vendor PHP Jabbers
Product Taxi Booking Script
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)
Vendor PHP Jabbers
Product Job Listing Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Property Listing Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)
Vendor PHP Jabbers
Product Travel Tours Script
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)
Vendor PHP Jabbers
Product Vacation Rental Script
Versions Default: unaffected
  • affected from 0 to 5.1 (excl.)
Vendor PHP Jabbers
Product Yacht Listing Script
Versions Default: unaffected
  • affected from 0 to 3.1 (excl.)

Credits

  • Kamil Szczurowski finder
  • Robert Kruczek finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-66 SQL Injection