Phpjabbers
Phpjabbers Class Scheduling System: vulnerabilities and CVEs
Phpjabbers Class Scheduling System has 4 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-36136 | Medium (6.5) | 0.28% | — | Aug 8, 2023 | PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text. |
| CVE-2023-36137 | Medium (6.1) | 0.36% | — | Aug 4, 2023 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0. |
| CVE-2023-36135 | High (7.5) | 0.56% | — | Aug 4, 2023 | User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not,… |
| CVE-2023-36134 | Critical (9.8) | 0.55% | — | Aug 4, 2023 | In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. |
Other products by Phpjabbers
Time Slots Booking Calendar · 9Cleaning Business Software · 9Availability Booking Calendar · 8Appointment Scheduler · 8Cinema Booking System · 8CAR Rental Script · 7Event Booking Calendar · 7Fundraising Script · 7Hotel Booking System · 6CAR Park Booking System · 5Document Creator · 5Callback Widget · 5