Client-Side Desynchronization Vulnerability in Member Login Script by PHPJabbers
CVE-2023-53878
Key Information:
- Vendor
PHPjabbers
- Status
- Vendor
- CVE Published:
- 15 December 2025
Badges
What is CVE-2023-53878?
The Member Login Script version 3.3 presents a client-side desynchronization vulnerability, where attackers can exploit the parsing of the Content-Length header. By crafting specific POST requests that include smuggled secondary requests, malicious actors can potentially bypass the standard server-side request processing controls, leading to unauthorized access and manipulation of system behaviors.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Member Login Script 3.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
