Cyber News / Article / Vulnerabilities in PHP Jabbers scripts

Vulnerabilities in PHP Jabbers scripts
CERT Polska has received a report about vulnerabilities in multiple PHP Jabbers scripts and participated in coordination of their disclosure.
The vulnerabilityCVE-2025-67649: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script. Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
The vulnerabilityCVE-2026-46593: A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user topjAdminPolls.controller.phpendpoint allows an authenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
The vulnerabilityCVE-2026-46594: A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
This issue was fixed in version 4.1.
The vulnerabilityCVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list in a CVE entry.
The vulnerabilityCVE-2025-67651: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list in a CVE entry.
These two vulnerabilities were fixed in versions specified in the following table:
We thank Kamil Szczurowski and Robert Kruczek for the responsible vulnerability report.
Related articles
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
1 day ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
4 days ago
Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever
2026-04-10
