CVE-2026-46593: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in PHP Jabbers PHP Poll Script
A SQL injection vulnerability exists in PHP Jabbers PHP Poll Script allowing an authenticated attacker to exploit improper input neutralization in the pjAdminPolls.controller.php endpoint. This vulnerability enables high-impact SQL injection attacks. The issue was fixed in version 4.1. The vulnerability has a high CVSS 4.0 score of 8.6.
AI Analysis
Technical Summary
CVE-2026-46593 is a SQL injection vulnerability in PHP Jabbers PHP Poll Script. The flaw arises from improper neutralization of user input at the pjAdminPolls.controller.php endpoint, permitting authenticated attackers to perform SQL injection attacks. This vulnerability was addressed and fixed in version 4.1 of the product.
Potential Impact
An authenticated attacker can exploit this vulnerability to execute arbitrary SQL commands on the backend database, potentially leading to data disclosure, data modification, or other impacts typical of SQL injection. The CVSS 4.0 score of 8.6 indicates a high severity with network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
Upgrade to PHP Jabbers PHP Poll Script version 4.1 or later, where this vulnerability has been fixed. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed beyond the fix in version 4.1, so verify with the vendor advisory for the latest remediation guidance.
CVE-2026-46593: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in PHP Jabbers PHP Poll Script
Description
A SQL injection vulnerability exists in PHP Jabbers PHP Poll Script allowing an authenticated attacker to exploit improper input neutralization in the pjAdminPolls.controller.php endpoint. This vulnerability enables high-impact SQL injection attacks. The issue was fixed in version 4.1. The vulnerability has a high CVSS 4.0 score of 8.6.
CVSS v4.0
Score 8.6high
Affected software
PHP Jabbers
PHP Poll Script
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46593 is a SQL injection vulnerability in PHP Jabbers PHP Poll Script. The flaw arises from improper neutralization of user input at the pjAdminPolls.controller.php endpoint, permitting authenticated attackers to perform SQL injection attacks. This vulnerability was addressed and fixed in version 4.1 of the product.
Potential Impact
An authenticated attacker can exploit this vulnerability to execute arbitrary SQL commands on the backend database, potentially leading to data disclosure, data modification, or other impacts typical of SQL injection. The CVSS 4.0 score of 8.6 indicates a high severity with network attack vector, low attack complexity, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
Upgrade to PHP Jabbers PHP Poll Script version 4.1 or later, where this vulnerability has been fixed. No other official remediation or temporary fixes are documented. Patch status is not explicitly confirmed beyond the fix in version 4.1, so verify with the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-05-15T13:52:51.435Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6c8dec6072d5e7467402d7
Added to database: 07/31/2026, 11:58:36 UTC
Last enriched: 08/07/2026, 14:34:43 UTC
Last updated: 09/14/2026, 22:01:34 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.