PT-2025-7302 · Phpjabbers · Phpjabbers Bus Reservation System

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2023-51319

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPJabbers Bus Reservation System version 1.1
Description The issue allows an attacker to execute remote code due to insufficient input validation in the Languages section Labels any parameters field in System Options, which is used to construct a CSV file. This insufficient validation enables a CSV Injection vulnerability.
Recommendations For PHPJabbers Bus Reservation System version 1.1, consider disabling the functionality that constructs CSV files from user-inputted data in the System Options until a patch is available. Restrict access to the Languages section to minimize the risk of exploitation. Avoid using the parameters field in System Options that is used for CSV file construction until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-51319

Affected Products

Phpjabbers Bus Reservation System