Description
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.


This issue was fixed in the versions specified in the affected products list.
Published: 2026-07-31
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery (CSRF) vulnerability was discovered in numerous PHP Jabbers scripts because the applications do not employ CSRF tokens or appropriate SameSite attributes. An attacker can craft a malicious request that is executed in the context of an authenticated administrator, allowing actions such as creating new administrative accounts. The result is a compromise of the integrity of the system’s administrative environment.

Affected Systems

All PHP Jabbers scripts listed in the advisory—including Appointment Scheduler, Auto Classifieds Script, Availability Booking Calendar, Bus Reservation System, Business Directory Script, Car Rental Script, Hotel Booking System, Member Login Script, PHP Newsletter Script, PHP Shopping Cart, and numerous booking and listing modules—are affected. No specific version numbers are provided; the fix applies to the versions noted in the vendor’s affected‑product list.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of successful exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it has not yet been observed in the wild. An attacker would likely need a victim’s authenticated session or a login cookie to deliver the forged request. If such a session exists, the lack of CSRF protection allows the attacker to perform privileged actions without the user’s consent.

Generated by OpenCVE AI on August 3, 2026 at 09:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest PHP Jabbers releases that contain the CSRF fix; check the vendor’s advisories for the exact patch versions.
  • Implement CSRF protection in all forms by adding unique, unpredictable tokens that are validated on the server side.
  • Configure the session cookie with a SameSite attribute (Strict or Lax) to reduce the risk of CSRF and review any custom code that may bypass the CSRF checks.

Generated by OpenCVE AI on August 3, 2026 at 09:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.
Title CSRF in PHP Jabbers scripts
First Time appeared Php Jabbers
Php Jabbers appointment Scheduler
Php Jabbers auto Classifieds Script
Php Jabbers availability Booking Calendar
Php Jabbers availability Calendar
Php Jabbers bus Reservation System
Php Jabbers business Directory Script
Php Jabbers car Park Booking System
Php Jabbers car Rental Script
Php Jabbers cinema Booking System
Php Jabbers cleaning Business Software
Php Jabbers equipment Rental Script
Php Jabbers event Booking Calendar
Php Jabbers event Ticketing System
Php Jabbers food Delivery Script
Php Jabbers hotel Booking System
Php Jabbers job Listing Script
Php Jabbers limo Booking Software
Php Jabbers meeting Room Booking System
Php Jabbers member Directory Script
Php Jabbers member Login Script
Php Jabbers php Event Calendar
Php Jabbers php Newsletter Script
Php Jabbers php Shopping Cart
Php Jabbers product Comparison Script
Php Jabbers property Listing Script
Php Jabbers rental Property Booking Calendar
Php Jabbers restaurant Booking System
Php Jabbers service Booking Script
Php Jabbers shuttle Booking Software
Php Jabbers taxi Booking Script
Php Jabbers ticket Support Script
Php Jabbers time Slots Booking Calendar
Php Jabbers travel Tours Script
Php Jabbers vacation Rental Script
Php Jabbers yacht Listing Script
Weaknesses CWE-352
CPEs cpe:2.3:a:php_jabbers:appointment_scheduler:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:auto_classifieds_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:availability_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:availability_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:bus_reservation_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:business_directory_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:car_park_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:car_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:cinema_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:cleaning_business_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:equipment_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:event_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:event_ticketing_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:food_delivery_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:hotel_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:job_listing_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:limo_booking_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:meeting_room_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:member_directory_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:member_login_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_event_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_newsletter_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:php_shopping_cart:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:product_comparison_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:property_listing_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:rental_property_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:restaurant_booking_system:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:service_booking_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:shuttle_booking_software:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:taxi_booking_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:ticket_support_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:time_slots_booking_calendar:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:travel_tours_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:vacation_rental_script:*:*:*:*:*:*:*:*
cpe:2.3:a:php_jabbers:yacht_listing_script:*:*:*:*:*:*:*:*
Vendors & Products Php Jabbers
Php Jabbers appointment Scheduler
Php Jabbers auto Classifieds Script
Php Jabbers availability Booking Calendar
Php Jabbers availability Calendar
Php Jabbers bus Reservation System
Php Jabbers business Directory Script
Php Jabbers car Park Booking System
Php Jabbers car Rental Script
Php Jabbers cinema Booking System
Php Jabbers cleaning Business Software
Php Jabbers equipment Rental Script
Php Jabbers event Booking Calendar
Php Jabbers event Ticketing System
Php Jabbers food Delivery Script
Php Jabbers hotel Booking System
Php Jabbers job Listing Script
Php Jabbers limo Booking Software
Php Jabbers meeting Room Booking System
Php Jabbers member Directory Script
Php Jabbers member Login Script
Php Jabbers php Event Calendar
Php Jabbers php Newsletter Script
Php Jabbers php Shopping Cart
Php Jabbers product Comparison Script
Php Jabbers property Listing Script
Php Jabbers rental Property Booking Calendar
Php Jabbers restaurant Booking System
Php Jabbers service Booking Script
Php Jabbers shuttle Booking Software
Php Jabbers taxi Booking Script
Php Jabbers ticket Support Script
Php Jabbers time Slots Booking Calendar
Php Jabbers travel Tours Script
Php Jabbers vacation Rental Script
Php Jabbers yacht Listing Script
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Php Jabbers Appointment Scheduler Auto Classifieds Script Availability Booking Calendar Availability Calendar Bus Reservation System Business Directory Script Car Park Booking System Car Rental Script Cinema Booking System Cleaning Business Software Equipment Rental Script Event Booking Calendar Event Ticketing System Food Delivery Script Hotel Booking System Job Listing Script Limo Booking Software Meeting Room Booking System Member Directory Script Member Login Script Php Event Calendar Php Newsletter Script Php Shopping Cart Product Comparison Script Property Listing Script Rental Property Booking Calendar Restaurant Booking System Service Booking Script Shuttle Booking Software Taxi Booking Script Ticket Support Script Time Slots Booking Calendar Travel Tours Script Vacation Rental Script Yacht Listing Script
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-31T19:52:27.724Z

Reserved: 2025-12-09T19:10:43.240Z

Link: CVE-2025-67651

cve-icon Vulnrichment

Updated: 2026-07-31T19:52:20.564Z

cve-icon NVD

Status : Received

Published: 2026-07-31T12:16:48.520

Modified: 2026-07-31T20:16:45.923

Link: CVE-2025-67651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:00:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)