CVE-2023-51319

HIGH

PHPJabbers Bus Reservation System v1.1 - Code Injection

Title source: llm

Description

PHPJabbers Bus Reservation System v1.1 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

Scores

CVSS v3 8.8
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-1236
Status published

Affected Products (1)

phpjabbers/bus_reservation_system

Timeline

Published Feb 20, 2025
Tracked Since Feb 18, 2026