CSV Injection Vulnerability in PHPJabbers Cinema Booking System
CVE-2023-51333
8.8HIGH
What is CVE-2023-51333?
The PHPJabbers Cinema Booking System v1.0 has a vulnerability stemming from inadequate input validation within the Languages section's Labels parameter in System Options. This flaw allows an attacker to craft malicious CSV files, which could lead to the execution of remote code when the files are processed. Proper validation and sanitization are crucial to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
