← Volver al buscador de CVEs

CVE-2025-67649

PHP Jabbers - Car Rental Script

Descripción

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

CVSS 9.3EPSS 0.27399999999999997%Riesgo 0.95
Ver fuente
Publicación
2026-07-31 12:16:48
Versiones afectadas
<4.1
Tipo
Aplicación web
Última modificación
2026-07-31 20:16:45
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X