<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 01:12:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-67651 — CSRF in PHP Jabbers scripts</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-67651</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Jabbers Appointment Scheduler, PHP Jabbers Bus Reservation System, PHP Jabbers Car Park Booking System, PHP Jabbers Car Rental Script, PHP Jabbers Cinema Booking System, PHP Jabbers Event Booking Calendar, PHP Jabbers Event Ticketing System, PHP Jabbers Hotel Booking System, PHP Jabbers Cleaning Business Software, PHP Jabbers Equipment Rental Script and 25 more&lt;/p&gt;
&lt;p&gt;A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.&lt;/p&gt;
&lt;p&gt;This issue was fixed in the versions specified in the affected products list.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PHP Jabbers Appointment Scheduler, PHP Jabbers Bus Reservation System, PHP Jabbers Car Park Booking System, PHP Jabbers Car Rental Script, PHP Jabbers Cinema Booking System, PHP Jabbers Event Booking Calendar, PHP Jabbers Event Ticketing System, PHP Jabbers Hotel Booking System, PHP Jabbers Cleaning Business Software, PHP Jabbers Equipment Rental Script and 25 more&lt;/p&gt;
&lt;p&gt;A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts.&lt;/p&gt;
&lt;p&gt;This issue was fixed in the versions specified in the affected products list.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-67651</guid>
    </item>
  </channel>
</rss>
