Vulnerabilities > Phpjabbers > Cleaning Business Software

DATE CVE VULNERABILITY TITLE RISK
2023-09-11 CVE-2023-36140 Missing Authorization vulnerability in PHPjabbers Cleaning Business Software 1.0
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
network
low complexity
phpjabbers CWE-862
critical
9.8
2023-08-04 CVE-2023-36138 Cross-site Scripting vulnerability in PHPjabbers Cleaning Business Software 1.0
PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.
network
low complexity
phpjabbers CWE-79
6.1
2023-08-04 CVE-2023-36139 Insufficient Verification of Data Authenticity vulnerability in PHPjabbers Cleaning Business Software 1.0
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
network
low complexity
phpjabbers CWE-345
critical
9.8
2023-08-04 CVE-2023-36141 Unspecified vulnerability in PHPjabbers Cleaning Business Software 1.0
User enumeration is found in in PHPJabbers Cleaning Business Software 1.0.
network
low complexity
phpjabbers
5.3
2023-08-03 CVE-2023-4115 Cross-site Scripting vulnerability in PHPjabbers Cleaning Business Software 1.0
A vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0.
network
low complexity
phpjabbers CWE-79
6.1