LiveActive security incident?Get immediate response
CVE Record

CVE-2025-67650: Authenticated SQL Injection in PHP Jabbers scripts

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in the affected products list.

HighCVSS 8.6Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Authenticated users with high privileges may be able to manipulate sorting inputs in multiple PHP Jabbers scripts, causing unsafe database queries. Successful abuse could expose or alter sensitive booking, customer, membership, or commerce data and may partially disrupt service.

Executive priority

Treat this as a high-priority investigation for organizations using PHP Jabbers scripts, especially systems holding customer, booking, payment-adjacent, or membership data. Prioritize inventory and privileged-account controls immediately, then patch confirmed vulnerable deployments. Current evidence does not justify claiming an active exploitation emergency.

Technical view

CVE-2025-67650 is a CWE-89 SQL injection caused by improper neutralization of authenticated sorting parameters. CVSS 4.0 scores it 8.6: network-accessible, low complexity, no user interaction, but requiring high privileges. Expected impact is high database confidentiality and integrity loss with limited availability impact.

Likely exposure

Exposure is limited to PHP Jabbers deployments running vulnerable releases where a high-privileged authenticated user can reach affected sorting functions. The supplied machine-readable entries do not provide usable vulnerable or fixed version ranges, so exposure cannot be determined from version data alone.

Exploitation context

The bundle provides no evidence of public or active exploitation, and the CVE is not identified as KEV. That does not prove exploitation is absent. Authentication and high privileges reduce initial access likelihood, while low attack complexity makes abuse consequential after privileged account compromise or misuse.

Researcher notes

The affected-product data is internally unhelpful: each entry reports version "0" with default status "unaffected," while the description says fixes exist in versions specified by the affected list. Consequently, the bundle supports the vulnerability mechanism and severity but not reliable affected or fixed release boundaries. The CERT.PL reference path also names CVE-2025-67649 rather than this CVE.

Mitigation direction

  • Inventory deployments of the listed PHP Jabbers products and record exact installed versions.
  • Obtain the authoritative affected and fixed version matrix from PHP Jabbers or the CVE record.
  • Upgrade confirmed vulnerable installations to vendor-designated fixed versions.
  • Restrict high-privileged accounts and remove unnecessary access while remediation is pending.
  • Monitor vendor guidance because the supplied sources name no separate workaround.

Validation and detection

  • Confirm every PHP Jabbers deployment, product edition, version, and internet exposure.
  • Compare installed versions against corrected vendor or CVE affected-version guidance.
  • Verify authenticated sorting functions are covered by the installed vendor fix.
  • Review application and database logs for unusual sorting requests, query errors, or unexpected data access.
  • Retest normal sorting and authorization behavior after upgrading.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-89: Database access and collection lookup

Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-67650 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.6 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.6CVSS 4.0HighCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:NCERT-PL

Vulnerability scoring details

Base CVSS 4.0 score

8.6High
CVSS 4.0 vector shape for CVE-2025-67650Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
PHP JabbersAppointment Scheduler0unaffected
PHP JabbersBus Reservation System0unaffected
PHP JabbersCar Park Booking System0unaffected
PHP JabbersCar Rental Script0unaffected
PHP JabbersCinema Booking System0unaffected
PHP JabbersEvent Booking Calendar0unaffected
PHP JabbersEvent Ticketing System0unaffected
PHP JabbersHotel Booking System0unaffected
PHP JabbersCleaning Business Software0unaffected
PHP JabbersEquipment Rental Script0unaffected
PHP JabbersFood Delivery Script0unaffected
PHP JabbersMember Login Script0unaffected
PHP JabbersMember Directory Script0unaffected
PHP JabbersAvailability Calendar0unaffected
PHP JabbersPHP Event Calendar0unaffected
PHP JabbersPHP Newsletter Script0unaffected
PHP JabbersProduct Comparison Script0unaffected
PHP JabbersTicket Support Script0unaffected
PHP JabbersPHP Shopping Cart0unaffected
PHP JabbersAuto Classifieds Script0unaffected
PHP JabbersBusiness Directory Script0unaffected
PHP JabbersAvailability Booking Calendar0unaffected
PHP JabbersTime Slots Booking Calendar0unaffected
PHP JabbersRestaurant Booking System0unaffected
PHP JabbersShuttle Booking Software0unaffected
PHP JabbersMeeting Room Booking System0unaffected
PHP JabbersRental Property Booking Calendar0unaffected
PHP JabbersService Booking Script0unaffected
PHP JabbersLimo Booking Software0unaffected
PHP JabbersTaxi Booking Script0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.