Phpjabbers
Phpjabbers Class Scheduling System: vulnerabilidades y CVE
Phpjabbers Class Scheduling System tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-36136 | Media (6.5) | 0.28% | — | 8 ago 2023 | PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text. |
| CVE-2023-36137 | Media (6.1) | 0.36% | — | 4 ago 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0. |
| CVE-2023-36135 | Alta (7.5) | 0.56% | — | 4 ago 2023 | User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not,… |
| CVE-2023-36134 | Crítica (9.8) | 0.55% | — | 4 ago 2023 | In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. |
Otros productos de Phpjabbers
Time Slots Booking Calendar · 9Cleaning Business Software · 9Availability Booking Calendar · 8Appointment Scheduler · 8Cinema Booking System · 8CAR Rental Script · 7Event Booking Calendar · 7Fundraising Script · 7Hotel Booking System · 6CAR Park Booking System · 5Document Creator · 5Callback Widget · 5