CVE-2025-67650: Authenticated SQL Injection in PHP Jabbers scripts
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks.
This issue was fixed in the versions specified in the affected products list.
Security readout for executives and security teams
Plain-English summary
Authenticated users with high privileges may be able to manipulate sorting inputs in multiple PHP Jabbers scripts, causing unsafe database queries. Successful abuse could expose or alter sensitive booking, customer, membership, or commerce data and may partially disrupt service.
Executive priority
Treat this as a high-priority investigation for organizations using PHP Jabbers scripts, especially systems holding customer, booking, payment-adjacent, or membership data. Prioritize inventory and privileged-account controls immediately, then patch confirmed vulnerable deployments. Current evidence does not justify claiming an active exploitation emergency.
Technical view
CVE-2025-67650 is a CWE-89 SQL injection caused by improper neutralization of authenticated sorting parameters. CVSS 4.0 scores it 8.6: network-accessible, low complexity, no user interaction, but requiring high privileges. Expected impact is high database confidentiality and integrity loss with limited availability impact.
Likely exposure
Exposure is limited to PHP Jabbers deployments running vulnerable releases where a high-privileged authenticated user can reach affected sorting functions. The supplied machine-readable entries do not provide usable vulnerable or fixed version ranges, so exposure cannot be determined from version data alone.
Exploitation context
The bundle provides no evidence of public or active exploitation, and the CVE is not identified as KEV. That does not prove exploitation is absent. Authentication and high privileges reduce initial access likelihood, while low attack complexity makes abuse consequential after privileged account compromise or misuse.
Researcher notes
The affected-product data is internally unhelpful: each entry reports version "0" with default status "unaffected," while the description says fixes exist in versions specified by the affected list. Consequently, the bundle supports the vulnerability mechanism and severity but not reliable affected or fixed release boundaries. The CERT.PL reference path also names CVE-2025-67649 rather than this CVE.
Mitigation direction
Inventory deployments of the listed PHP Jabbers products and record exact installed versions.
Obtain the authoritative affected and fixed version matrix from PHP Jabbers or the CVE record.
Upgrade confirmed vulnerable installations to vendor-designated fixed versions.
Restrict high-privileged accounts and remove unnecessary access while remediation is pending.
Monitor vendor guidance because the supplied sources name no separate workaround.
Validation and detection
Confirm every PHP Jabbers deployment, product edition, version, and internet exposure.
Compare installed versions against corrected vendor or CVE affected-version guidance.
Verify authenticated sorting functions are covered by the installed vendor fix.
Review application and database logs for unusual sorting requests, query errors, or unexpected data access.
Retest normal sorting and authorization behavior after upgrading.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-89: Database access and collection lookup
Injection into data stores can inform collection, data access, and exfiltration detection reviews. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.