CSV Injection Vulnerability in PHPJabbers Restaurant Booking System
CVE-2023-51313

8.8HIGH

Key Information:

Vendor
PHPJabbers
Vendor
CVE Published:
20 February 2025

Summary

The Restaurant Booking System v3.0 from PHPJabbers is susceptible to a CSV injection vulnerability, allowing attackers to execute remote code. This issue arises from inadequate input validation in the Languages section Labels field within the System Options, which is utilized for generating CSV files. Exploiting this vulnerability could result in unauthorized command execution on the server, jeopardizing the integrity of the application and its users.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.