PHPJabbers Appointment Scheduler是PHPJabbers公司的一款预约调度软件 PHPJabbers Appointment Scheduler 4.1之前版本存在跨站请求伪造漏洞,该漏洞源于缺乏CSRF令牌或适当的SameSite属性,可能导致攻击者在已认证用户环境下发送未经授权的请求,从而执行未授权的管理操作,如创建新的管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-67649 | 9.3 CRITICAL | Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script |
| CVE-2026-46593 | 8.6 HIGH | Authenticated SQL Injection in PHP Poll Script |
| CVE-2025-67650 | 8.6 HIGH | Authenticated SQL Injection in PHP Jabbers scripts |
| CVE-2026-46594 | 5.1 MEDIUM | Reflected XSS in PHP Poll Script |
No comments yet