Executive brief
A security vulnerability has been identified in over 30 different PHP Jabbers scripts, which are widely used for online booking, e-commerce, and directory services. An attacker with existing account access could exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive customer information, modification of business data, or disruption of booking services.
Technical details
An authenticated SQL injection vulnerability (CWE-89) exists in multiple PHP Jabbers scripts due to improper neutralization of user-supplied input in parameters responsible for sorting functions. The vulnerability requires high privileges (PR:H) to exploit but allows for significant impact on data confidentiality and integrity (VC:H/VI:H). Attackers can manipulate SQL queries to extract or modify data from the database. The issue has been addressed in various updated versions across the product line, such as Appointment Scheduler 4.1 and Hotel Booking System 5.1.
Affected products
- PHP Jabbers Appointment Scheduler before 4.1
- PHP Jabbers Bus Reservation System before 2.1
- PHP Jabbers Car Park Booking System before 4.1
- PHP Jabbers Car Rental Script before 4.1
- PHP Jabbers Cinema Booking System before 2.1
- PHP Jabbers Event Booking Calendar before 5.1
- PHP Jabbers Event Ticketing System before 2.1
- PHP Jabbers Hotel Booking System before 5.1
- PHP Jabbers Cleaning Business Software before 2.1
- PHP Jabbers Equipment Rental Script before 2.1
- PHP Jabbers Food Delivery Script before 4.1
- PHP Jabbers Member Login Script before 4.1
- PHP Jabbers Member Directory Script before 2.1
- PHP Jabbers Availability Calendar before 6.1
- PHP Jabbers PHP Event Calendar before 4.1
- PHP Jabbers PHP Newsletter Script before 5.1
- PHP Jabbers Product Comparison Script before 2.1
- PHP Jabbers Ticket Support Script before 4.1
- PHP Jabbers PHP Shopping Cart before 6.0
- PHP Jabbers Auto Classifieds Script before 4.1
- PHP Jabbers, Business Directory Script before 4.1
- PHP Jabbers Availability Booking Calendar before 6.1
- PHP Jabbers Time Slots Booking Calendar before 5.1
- PHP Jabbers Restaurant Booking System before 4.1
- PHP Jabbers Shuttle Booking Software before 3.1
- PHP Jabbers Meeting Room Booking System before 2.1
- PHP Jabbers Rental Property Booking Calendar before 3.1
- PHP Jabbers Service Booking Script before 2.1
- PHP Jabbers Limo Booking Software before 2.1
- PHP Jabbers Taxi Booking Script before 3.1
- PHP Jabbers Job Listing Script before 4.1
- PHP Jabbers Property Listing Script before 4.1
- PHP Jabbers Travel Tours Script before 3.1
- PHP Jabbers Vacation Rental Script before 5.1
- PHP Jabbers Yacht Listing Script before 3.1
Timeline
- 2026-07-31: disclosed: Vulnerability disclosed by CERT.PL
- 2026-07-31: patched: Fixes released for affected products