CSRF in PHP Jabbers scripts
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.9epss 0.2%
probabilidad de explotación
0.2%top 94% de las CVE
explotación observada
noninguna fuente lo reporta
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.
This issue was fixed in the versions specified in the affected products list.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
PHP Jabbers · Appointment SchedulerPHP Jabbers · Auto Classifieds ScriptPHP Jabbers · Availability Booking CalendarPHP Jabbers · Availability CalendarPHP Jabbers · Business Directory ScriptPHP Jabbers · Bus Reservation SystemPHP Jabbers · Car Park Booking SystemPHP Jabbers · Car Rental ScriptPHP Jabbers · Cinema Booking SystemPHP Jabbers · Cleaning Business SoftwarePHP Jabbers · Equipment Rental ScriptPHP Jabbers · Event Booking CalendarPHP Jabbers · Event Ticketing SystemPHP Jabbers · Food Delivery ScriptPHP Jabbers · Hotel Booking SystemPHP Jabbers · Job Listing ScriptPHP Jabbers · Limo Booking SoftwarePHP Jabbers · Meeting Room Booking SystemPHP Jabbers · Member Directory ScriptPHP Jabbers · Member Login ScriptPHP Jabbers · PHP Event CalendarPHP Jabbers · PHP Newsletter ScriptPHP Jabbers · PHP Shopping CartPHP Jabbers · Product Comparison ScriptPHP Jabbers · Property Listing ScriptPHP Jabbers · Rental Property Booking CalendarPHP Jabbers · Restaurant Booking SystemPHP Jabbers · Service Booking ScriptPHP Jabbers · Shuttle Booking SoftwarePHP Jabbers · Taxi Booking ScriptPHP Jabbers · Ticket Support ScriptPHP Jabbers · Time Slots Booking CalendarPHP Jabbers · Travel Tours ScriptPHP Jabbers · Vacation Rental ScriptPHP Jabbers · Yacht Listing Script