CVE-2026-46593 PUBLISHED

Authenticated SQL Injection in PHP Poll Script

Assigner: CERT-PL
Reserved: 15.05.2026 Published: 31.07.2026 Updated: 31.07.2026

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor PHP Jabbers
Product PHP Poll Script
Versions Default: unaffected
  • affected from 0 to 4.1 (excl.)

Credits

  • Kamil Szczurowski finder
  • Robert Kruczek finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection