CRITICAL🇵🇱 Wersja polska

CVE-2023-53877

CVSS 9.3v4.0pub. 2025-12-15upd. 2025-12-18

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

🤖 AI Analysis
How it works

Attackers can inject malicious SQL code fragments through the pickup_id parameter in HTTP requests without needing any privileges. The vulnerability enables the use of three techniques: boolean-based blind SQL injection (inferring data based on true/false responses), error-based SQL injection (extracting information from database error messages), and time-based blind SQL injection (inferring data based on server response time). All three techniques allow gradual extraction of database contents despite the lack of direct display of query results.

Impact

Attackers can read or modify data stored in the application's database, including potentially personal passenger data, reservations, and authentication credentials. High level of impact on data confidentiality and integrity may lead to data theft or unauthorized modification.

Mitigation & patch

Apply patches available from the vendor according to references. Additionally, it is recommended to implement validation and parameterization of SQL queries on the server side, as well as to restrict access to the application at the firewall level to trusted IP addresses, if possible.

Who is affected

PHPJabbers Bus Reservation System version 1.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Phpjabbers Bus Reservation System

    APP
    Phpjabbers
    1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-51316HIGH7.5same product

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Bus Reservation System v1.1 allows atta...

CVE-2023-51319HIGH8.8same product

PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker t...

CVE-2023-51318MEDIUM5.4same product

PHPJabbers Bus Reservation System v1.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "tit...

CVE-2023-4111MEDIUM4.3same product

A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by...

CVE-2024-57428CRITICAL9.3PL ✓same vendor

Stored XSS w PHPJabbers Cinema Booking System v2.0