CRITICAL🇵🇱 Wersja polska

CVE-2023-36140

CVSS 9.8v3.1pub. 2023-09-11upd. 2024-11-21

In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Phpjabbers Cleaning Business Software

    APP
    Phpjabbers
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36139CRITICAL9.8PL ✓same product

PHPJabbers Cleaning Business Software — przejęcie konta przez brak weryfikacji

CVE-2023-51328MEDIUM5.4same product

PHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the ...

CVE-2023-51331MEDIUM6.5same product

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attack...

CVE-2023-51326MEDIUM6.5same product

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows ...

CVE-2023-51327MEDIUM6.5same product

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows ...