CVE-2023-38830

HIGH

PHPJabbers Yacht Listing Script <1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

Scores

CVSS v3 7.5
EPSS 0.0009
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (1)
phpjabbers/yacht_listing_script 1.0
Published Aug 10, 2023
Tracked Since Feb 18, 2026