CVE-2025-67650

HIGHCVSS 8.6/10

Last modified

CVE-2025-67650 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list..

Description

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

Metrics

CVSS 4.0
8.6/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
PHP JabbersAppointment Scheduler< 4.1
PHP JabbersBus Reservation System< 2.1
PHP JabbersCar Park Booking System< 4.1
PHP JabbersCar Rental Script< 4.1
PHP JabbersCinema Booking System< 2.1
PHP JabbersEvent Booking Calendar< 5.1
PHP JabbersEvent Ticketing System< 2.1
PHP JabbersHotel Booking System< 5.1
PHP JabbersCleaning Business Software< 2.1
PHP JabbersEquipment Rental Script< 2.1
PHP JabbersFood Delivery Script< 4.1
PHP JabbersMember Login Script< 4.1
PHP JabbersMember Directory Script< 2.1
PHP JabbersAvailability Calendar< 6.1
PHP JabbersPHP Event Calendar< 4.1
PHP JabbersPHP Newsletter Script< 5.1
PHP JabbersProduct Comparison Script< 2.1
PHP JabbersTicket Support Script< 4.1
PHP JabbersPHP Shopping Cart< 6.0
PHP JabbersAuto Classifieds Script< 4.1
PHP JabbersBusiness Directory Script< 4.1
PHP JabbersAvailability Booking Calendar< 6.1
PHP JabbersTime Slots Booking Calendar< 5.1
PHP JabbersRestaurant Booking System< 4.1
PHP JabbersShuttle Booking Software< 3.1
PHP JabbersMeeting Room Booking System< 2.1
PHP JabbersRental Property Booking Calendar< 3.1
PHP JabbersService Booking Script< 2.1
PHP JabbersLimo Booking Software< 2.1
PHP JabbersTaxi Booking Script< 3.1
PHP JabbersJob Listing Script< 4.1
PHP JabbersProperty Listing Script< 4.1
PHP JabbersTravel Tours Script< 3.1
PHP JabbersVacation Rental Script< 5.1
PHP JabbersYacht Listing Script< 3.1

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2025-67650?
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.
How severe is CVE-2025-67650?
CVE-2025-67650 has a CVSS score of 8.6/10 (HIGH severity).
How do I fix CVE-2025-67650?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-67650?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST