CVE-2025-67651: CWE-352 Cross-Site Request Forgery (CSRF) in PHP Jabbers Appointment Scheduler
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple PHP Jabbers Appointment Scheduler scripts due to missing CSRF tokens or appropriate SameSite cookie attributes. This flaw allows attackers to perform unauthorized actions on behalf of authenticated users, including creating new administrative accounts. The vulnerability has a medium severity score of 6.9 and has been assigned CVE-2025-67651. The issue is known and published but no specific affected versions or patches have been provided in the available data.
AI Analysis
Technical Summary
CVE-2025-67651 is a CSRF vulnerability in PHP Jabbers Appointment Scheduler where the absence of CSRF tokens or proper SameSite cookie attributes enables attackers to send unauthorized requests within the context of an authenticated user session. This can lead to unauthorized administrative actions such as creating new admin accounts. The vulnerability has a CVSS 4.0 base score of 6.9 (medium severity). Although the description states that the issue was fixed in certain versions, no explicit affected versions or patch details are provided in the input data. No known exploits in the wild have been reported.
Potential Impact
An attacker can exploit this vulnerability to perform unauthorized administrative actions, including creating new admin accounts, by tricking an authenticated user into submitting malicious requests. This can compromise the integrity and control of the affected Appointment Scheduler installation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description indicates that fixes exist in certain versions, so users should consult PHP Jabbers for official patches or updates. Until patched, users should consider implementing CSRF protections such as CSRF tokens and enforcing SameSite cookie attributes if possible.
CVE-2025-67651: CWE-352 Cross-Site Request Forgery (CSRF) in PHP Jabbers Appointment Scheduler
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple PHP Jabbers Appointment Scheduler scripts due to missing CSRF tokens or appropriate SameSite cookie attributes. This flaw allows attackers to perform unauthorized actions on behalf of authenticated users, including creating new administrative accounts. The vulnerability has a medium severity score of 6.9 and has been assigned CVE-2025-67651. The issue is known and published but no specific affected versions or patches have been provided in the available data.
CVSS v4.0
Score 6.9medium
Affected software
PHP Jabbers
Appointment Scheduler
PHP Jabbers
Bus Reservation System
PHP Jabbers
Car Park Booking System
PHP Jabbers
Car Rental Script
PHP Jabbers
Cinema Booking System
PHP Jabbers
Event Booking Calendar
PHP Jabbers
Event Ticketing System
PHP Jabbers
Hotel Booking System
PHP Jabbers
Cleaning Business Software
PHP Jabbers
Equipment Rental Script
PHP Jabbers
Food Delivery Script
PHP Jabbers
Member Login Script
PHP Jabbers
Member Directory Script
PHP Jabbers
Availability Calendar
PHP Jabbers
PHP Event Calendar
PHP Jabbers
PHP Newsletter Script
PHP Jabbers
Product Comparison Script
PHP Jabbers
Ticket Support Script
PHP Jabbers
PHP Shopping Cart
PHP Jabbers
Auto Classifieds Script
PHP Jabbers
Business Directory Script
PHP Jabbers
Availability Booking Calendar
PHP Jabbers
Time Slots Booking Calendar
PHP Jabbers
Restaurant Booking System
PHP Jabbers
Shuttle Booking Software
PHP Jabbers
Meeting Room Booking System
PHP Jabbers
Rental Property Booking Calendar
PHP Jabbers
Service Booking Script
PHP Jabbers
Limo Booking Software
PHP Jabbers
Taxi Booking Script
PHP Jabbers
Job Listing Script
PHP Jabbers
Property Listing Script
PHP Jabbers
Travel Tours Script
PHP Jabbers
Vacation Rental Script
PHP Jabbers
Yacht Listing Script
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-67651 is a CSRF vulnerability in PHP Jabbers Appointment Scheduler where the absence of CSRF tokens or proper SameSite cookie attributes enables attackers to send unauthorized requests within the context of an authenticated user session. This can lead to unauthorized administrative actions such as creating new admin accounts. The vulnerability has a CVSS 4.0 base score of 6.9 (medium severity). Although the description states that the issue was fixed in certain versions, no explicit affected versions or patch details are provided in the input data. No known exploits in the wild have been reported.
Potential Impact
An attacker can exploit this vulnerability to perform unauthorized administrative actions, including creating new admin accounts, by tricking an authenticated user into submitting malicious requests. This can compromise the integrity and control of the affected Appointment Scheduler installation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The description indicates that fixes exist in certain versions, so users should consult PHP Jabbers for official patches or updates. Until patched, users should consider implementing CSRF protections such as CSRF tokens and enforcing SameSite cookie attributes if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2025-12-09T19:10:43.240Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6c8dec6072d5e7467402d3
Added to database: 07/31/2026, 11:58:36 UTC
Last enriched: 08/07/2026, 14:33:18 UTC
Last updated: 09/15/2026, 22:01:30 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.