Executive brief
PHP Jabbers Car Rental Script, a web-based booking system for rental businesses, contains a critical security flaw. An attacker can exploit this vulnerability to gain unauthorized access to the underlying database, potentially leading to the theft of customer information, reservation data, and administrative credentials. This could result in significant data breaches and operational disruption for car rental companies using the software.
Technical details
A SQL injection vulnerability exists in PHP Jabbers Car Rental Script due to improper neutralization of user-supplied input in parameters used for sorting functions. An unauthenticated remote attacker can exploit this by sending specially crafted web requests to the application. Successful exploitation allows the attacker to read, modify, or delete data within the database, potentially leading to full system compromise. The issue is addressed in version 4.1, which includes security hardening and CSRF protection.
Affected products
- PHP Jabbers Car Rental Script All versions before 4.1
Timeline
- 2026-07-31: disclosed: Advisory published by CERT Polska
- 2026-06-01: patched: Version 4.1 released with security fixes