CVE-2025-67650: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') in PHP Jabbers Appointment Scheduler
CVE-2025-67650 is an authenticated SQL injection vulnerability in multiple PHP Jabbers scripts, specifically in the Appointment Scheduler product. The flaw arises from improper neutralization of input provided by authenticated users in parameters related to sorting functions, enabling SQL injection attacks. This vulnerability has a high severity score of 8.6 and was published in July 2026. The issue has been fixed in certain versions, though those specific versions are not listed in the provided data.
AI Analysis
Technical Summary
An authenticated SQL injection vulnerability (CWE-89) exists in PHP Jabbers Appointment Scheduler due to improper neutralization of special elements in SQL commands. Authenticated users can manipulate input parameters responsible for sorting functions, leading to potential SQL injection attacks. The vulnerability is rated high severity with a CVSS 4.0 score of 8.6, indicating network attack vector, low attack complexity, no user interaction, and high impact on confidentiality, integrity, and availability. No explicit patch or remediation details are provided in the available data.
Potential Impact
Successful exploitation allows an authenticated attacker to perform SQL injection attacks, potentially leading to unauthorized data access, data modification, or disruption of service within the affected PHP Jabbers Appointment Scheduler scripts. The high CVSS score reflects significant impact on confidentiality, integrity, and availability of the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description notes that the issue was fixed in certain versions, but no specific patch links or fixed versions are provided. Users should consult PHP Jabbers official advisories to identify and apply the appropriate updates. Until patched, restrict authenticated user privileges to minimize risk.
CVE-2025-67650: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') in PHP Jabbers Appointment Scheduler
Description
CVE-2025-67650 is an authenticated SQL injection vulnerability in multiple PHP Jabbers scripts, specifically in the Appointment Scheduler product. The flaw arises from improper neutralization of input provided by authenticated users in parameters related to sorting functions, enabling SQL injection attacks. This vulnerability has a high severity score of 8.6 and was published in July 2026. The issue has been fixed in certain versions, though those specific versions are not listed in the provided data.
CVSS v4.0
Score 8.6high
Affected software
PHP Jabbers
Appointment Scheduler
PHP Jabbers
Bus Reservation System
PHP Jabbers
Car Park Booking System
PHP Jabbers
Car Rental Script
PHP Jabbers
Cinema Booking System
PHP Jabbers
Event Booking Calendar
PHP Jabbers
Event Ticketing System
PHP Jabbers
Hotel Booking System
PHP Jabbers
Cleaning Business Software
PHP Jabbers
Equipment Rental Script
PHP Jabbers
Food Delivery Script
PHP Jabbers
Member Login Script
PHP Jabbers
Member Directory Script
PHP Jabbers
Availability Calendar
PHP Jabbers
PHP Event Calendar
PHP Jabbers
PHP Newsletter Script
PHP Jabbers
Product Comparison Script
PHP Jabbers
Ticket Support Script
PHP Jabbers
PHP Shopping Cart
PHP Jabbers
Auto Classifieds Script
PHP Jabbers
Business Directory Script
PHP Jabbers
Availability Booking Calendar
PHP Jabbers
Time Slots Booking Calendar
PHP Jabbers
Restaurant Booking System
PHP Jabbers
Shuttle Booking Software
PHP Jabbers
Meeting Room Booking System
PHP Jabbers
Rental Property Booking Calendar
PHP Jabbers
Service Booking Script
PHP Jabbers
Limo Booking Software
PHP Jabbers
Taxi Booking Script
PHP Jabbers
Job Listing Script
PHP Jabbers
Property Listing Script
PHP Jabbers
Travel Tours Script
PHP Jabbers
Vacation Rental Script
PHP Jabbers
Yacht Listing Script
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An authenticated SQL injection vulnerability (CWE-89) exists in PHP Jabbers Appointment Scheduler due to improper neutralization of special elements in SQL commands. Authenticated users can manipulate input parameters responsible for sorting functions, leading to potential SQL injection attacks. The vulnerability is rated high severity with a CVSS 4.0 score of 8.6, indicating network attack vector, low attack complexity, no user interaction, and high impact on confidentiality, integrity, and availability. No explicit patch or remediation details are provided in the available data.
Potential Impact
Successful exploitation allows an authenticated attacker to perform SQL injection attacks, potentially leading to unauthorized data access, data modification, or disruption of service within the affected PHP Jabbers Appointment Scheduler scripts. The high CVSS score reflects significant impact on confidentiality, integrity, and availability of the system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description notes that the issue was fixed in certain versions, but no specific patch links or fixed versions are provided. Users should consult PHP Jabbers official advisories to identify and apply the appropriate updates. Until patched, restrict authenticated user privileges to minimize risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2025-12-09T19:10:43.240Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6c8dec6072d5e7467402cf
Added to database: 07/31/2026, 11:58:36 UTC
Last enriched: 08/07/2026, 14:33:05 UTC
Last updated: 09/11/2026, 07:31:51 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.