Vulnerabilities > Phpjabbers > CAR Rental Script

DATE CVE VULNERABILITY TITLE RISK
2023-12-07 CVE-2023-48834 Resource Exhaustion vulnerability in PHPjabbers CAR Rental Script 3.0
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
network
low complexity
phpjabbers CWE-400
7.5
2023-12-07 CVE-2023-48835 Injection vulnerability in PHPjabbers CAR Rental Script 3.0
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
network
low complexity
phpjabbers CWE-74
8.8
2023-12-07 CVE-2023-48836 Cross-site Scripting vulnerability in PHPjabbers CAR Rental Script 3.0
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
network
low complexity
phpjabbers CWE-79
5.4
2023-12-07 CVE-2023-48837 Cross-site Scripting vulnerability in PHPjabbers CAR Rental Script 3.0
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
network
low complexity
phpjabbers CWE-79
5.4
2023-08-28 CVE-2023-40754 Incorrect Permission Assignment for Critical Resource vulnerability in PHPjabbers CAR Rental Script 3.0
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-732
8.8
2023-08-28 CVE-2023-40764 Information Exposure Through an Error Message vulnerability in PHPjabbers CAR Rental Script 3.0
User enumeration is found in PHP Jabbers Car Rental Script v3.0.
network
low complexity
phpjabbers CWE-209
critical
9.8