Cross-Site Request Forgery Vulnerabilities in PHPJabbers Appointment Scheduler by PHPJabbers
CVE-2014-10001

Currently unrated

Key Information:

Vendor

PHPjabbers

Vendor
CVE Published:
13 January 2015

What is CVE-2014-10001?

PHPJabbers Appointment Scheduler version 2.0 contains multiple cross-site request forgery (CSRF) vulnerabilities that may allow attackers to exploit the application's functionality. By manipulating the i18n[name] parameter in specific actions, an attacker could potentially execute cross-site scripting (XSS) attacks through the pjAdminServices controller. Additionally, unauthorized users may gain the ability to add administrative accounts via the pjAdminUsers controller, compromising system integrity and administrative controls.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.