Description
A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
This issue was fixed in version 4.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Title | Authenticated SQL Injection in PHP Poll Script | |
| First Time appeared |
Php Jabbers
Php Jabbers php Poll Script |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:php_jabbers:php_poll_script:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php Jabbers
Php Jabbers php Poll Script |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-31T19:53:03.540Z
Reserved: 2026-05-15T13:52:51.435Z
Link: CVE-2026-46593
Updated: 2026-07-31T19:52:59.305Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')