CVE-2025-67651

MEDIUMCVSS 6.9/10

Last modified

CVE-2025-67651 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list..

Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.

Metrics

CVSS 4.0
6.9/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
PHP JabbersAppointment Scheduler< 4.1
PHP JabbersBus Reservation System< 2.1
PHP JabbersCar Park Booking System< 4.1
PHP JabbersCar Rental Script< 4.1
PHP JabbersCinema Booking System< 2.1
PHP JabbersEvent Booking Calendar< 5.1
PHP JabbersEvent Ticketing System< 2.1
PHP JabbersHotel Booking System< 5.1
PHP JabbersCleaning Business Software< 2.1
PHP JabbersEquipment Rental Script< 2.1
PHP JabbersFood Delivery Script< 4.1
PHP JabbersMember Login Script< 4.1
PHP JabbersMember Directory Script< 2.1
PHP JabbersAvailability Calendar< 6.1
PHP JabbersPHP Event Calendar< 4.1
PHP JabbersPHP Newsletter Script< 5.1
PHP JabbersProduct Comparison Script< 2.1
PHP JabbersTicket Support Script< 4.1
PHP JabbersPHP Shopping Cart< 6.0
PHP JabbersAuto Classifieds Script< 4.1
PHP JabbersBusiness Directory Script< 4.1
PHP JabbersAvailability Booking Calendar< 6.1
PHP JabbersTime Slots Booking Calendar< 5.1
PHP JabbersRestaurant Booking System< 4.1
PHP JabbersShuttle Booking Software< 3.1
PHP JabbersMeeting Room Booking System< 2.1
PHP JabbersRental Property Booking Calendar< 3.1
PHP JabbersService Booking Script< 2.1
PHP JabbersLimo Booking Software< 2.1
PHP JabbersTaxi Booking Script< 3.1
PHP JabbersJob Listing Script< 4.1
PHP JabbersProperty Listing Script< 4.1
PHP JabbersTravel Tours Script< 3.1
PHP JabbersVacation Rental Script< 5.1
PHP JabbersYacht Listing Script< 3.1

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2025-67651?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.
How severe is CVE-2025-67651?
CVE-2025-67651 has a CVSS score of 6.9/10 (MEDIUM severity).
How do I fix CVE-2025-67651?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-67651?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST