// For flags

CVE-2023-48837

PHPJabbers Car Rental 3.0 HTML Injection

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (3)
NVD, NVD, PS
CWE (1)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC (-)
Risk
CVSS Score
5.4 Medium
SSVC
-
KEV
-
EPSS
0.1%
Affected Products (-)
Vendors (1)
phpjabbers
Products (1)
car_rental_script
Versions (1)
3.0
Intel Resources (1)
Advisories (-)
-
Exploits (1)
PacketStorm
Plugins (-)
-
References (3)
General (1)
phpjabbers
Exploits & POcs (2)
packetstorm, packetstormsecurity
Patches (-)
Advisories (-)
Summary
Descriptions

Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

Car Rental Script 3.0 es vulnerable a múltiples problemas de inyección de HTML a través de una clave API de SMS o un código de país predeterminado.

PHPJabbers Car Rental version 3.0 suffers from an html injection vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-11-20 CVE Reserved
  • 2023-12-04 CVE Published
  • 2023-12-04 First Exploit
  • 2024-08-02 CVE Updated
  • 2024-12-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Threat Intelligence Resources (1)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Phpjabbers
Search vendor "Phpjabbers"
Car Rental Script
Search vendor "Phpjabbers" for product "Car Rental Script"
3.0
Search vendor "Phpjabbers" for product "Car Rental Script" and version "3.0"
-
Affected