CSV Injection Vulnerability in Car Rental Script by PHPJabbers
CVE-2023-48835

8.8HIGH

Key Information:

Vendor
PHPjabbers
Vendor
CVE Published:
7 December 2023

Summary

The Car Rental Script v3.0 by PHPJabbers is susceptible to CSV Injection, which occurs through the Language > Labels > Export function. This vulnerability allows unauthorized users to manipulate exported CSV files, potentially leading to data exfiltration and execution of arbitrary commands when files are opened in spreadsheet applications. It is crucial for users of this script to apply security measures to prevent exploitation and safeguard sensitive information.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.