HIGH🇵🇱 Wersja polska

CVE-2023-51302

CVSS 8.8v3.1pub. 2025-02-19upd. 2025-04-23

PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Phpjabbers Hotel Booking System

    APP
    Phpjabbers
    4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-40760CRITICAL9.8PL ✓same product

User enumeration w PHPJabbers Hotel Booking System v4.0

CVE-2023-51301HIGH7.5same product

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 a...

CVE-2023-51297MEDIUM6.5same product

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attacke...

CVE-2023-51299MEDIUM6.1same product

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_...

CVE-2023-51300MEDIUM6.1same product

PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name,...