Cross-Site Request Forgery Vulnerabilities in PHPJabbers Appointment Scheduler by PHPJabbers
CVE-2014-10001
Currently unrated
What is CVE-2014-10001?
PHPJabbers Appointment Scheduler version 2.0 contains multiple cross-site request forgery (CSRF) vulnerabilities that may allow attackers to exploit the application's functionality. By manipulating the i18n[name] parameter in specific actions, an attacker could potentially execute cross-site scripting (XSS) attacks through the pjAdminServices controller. Additionally, unauthorized users may gain the ability to add administrative accounts via the pjAdminUsers controller, compromising system integrity and administrative controls.