CVE-2025-67651
Last modified
CVE-2025-67651 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list..
Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| PHP Jabbers | Appointment Scheduler | < 4.1 |
| PHP Jabbers | Bus Reservation System | < 2.1 |
| PHP Jabbers | Car Park Booking System | < 4.1 |
| PHP Jabbers | Car Rental Script | < 4.1 |
| PHP Jabbers | Cinema Booking System | < 2.1 |
| PHP Jabbers | Event Booking Calendar | < 5.1 |
| PHP Jabbers | Event Ticketing System | < 2.1 |
| PHP Jabbers | Hotel Booking System | < 5.1 |
| PHP Jabbers | Cleaning Business Software | < 2.1 |
| PHP Jabbers | Equipment Rental Script | < 2.1 |
| PHP Jabbers | Food Delivery Script | < 4.1 |
| PHP Jabbers | Member Login Script | < 4.1 |
| PHP Jabbers | Member Directory Script | < 2.1 |
| PHP Jabbers | Availability Calendar | < 6.1 |
| PHP Jabbers | PHP Event Calendar | < 4.1 |
| PHP Jabbers | PHP Newsletter Script | < 5.1 |
| PHP Jabbers | Product Comparison Script | < 2.1 |
| PHP Jabbers | Ticket Support Script | < 4.1 |
| PHP Jabbers | PHP Shopping Cart | < 6.0 |
| PHP Jabbers | Auto Classifieds Script | < 4.1 |
| PHP Jabbers | Business Directory Script | < 4.1 |
| PHP Jabbers | Availability Booking Calendar | < 6.1 |
| PHP Jabbers | Time Slots Booking Calendar | < 5.1 |
| PHP Jabbers | Restaurant Booking System | < 4.1 |
| PHP Jabbers | Shuttle Booking Software | < 3.1 |
| PHP Jabbers | Meeting Room Booking System | < 2.1 |
| PHP Jabbers | Rental Property Booking Calendar | < 3.1 |
| PHP Jabbers | Service Booking Script | < 2.1 |
| PHP Jabbers | Limo Booking Software | < 2.1 |
| PHP Jabbers | Taxi Booking Script | < 3.1 |
| PHP Jabbers | Job Listing Script | < 4.1 |
| PHP Jabbers | Property Listing Script | < 4.1 |
| PHP Jabbers | Travel Tours Script | < 3.1 |
| PHP Jabbers | Vacation Rental Script | < 5.1 |
| PHP Jabbers | Yacht Listing Script | < 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-67651?
How severe is CVE-2025-67651?
How do I fix CVE-2025-67651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67646TableProgressTracking is a MediaWiki extension to track prog…3.5
- CVE-2025-67647SvelteKit is a framework for rapidly developing robust, perf…9.1
- CVE-2025-67648Shopware is an open commerce platform. Versions 6.4.6.0 thro…6.1
- CVE-2025-67649A SQL injection vulnerability has been identified in PHP Jab…9.3
- CVE-2025-6765A vulnerability, which was classified as critical, has been …8.8
- CVE-2025-67650An authenticated SQL injection vulnerability has been identi…8.6
- CVE-2025-67652An attacker with access to the project file could use the ex…6.1
- CVE-2025-67653Advantech WebAccess/SCADA is vulnerable to directory travers…7.5
- CVE-2025-6766A vulnerability was found in sfturing hosp_order up to 627f4…8.8
- CVE-2025-6767A vulnerability was found in sfturing hosp_order up to 627f4…6.3
- CVE-2025-6768A vulnerability classified as critical has been found in sft…6.3
- CVE-2025-67683Quick.Cart is vulnerable to reflected XSS via the sSort para…6.1
Are you affected by CVE-2025-67651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
