PHPJabbers Event Booking Calendar
cpe:2.3:a:phpjabbers:event_booking_calendar:*:*:*:*:*:*:*
- 4.0
A CSV injection vulnerability has been identified in PHPJabbers Event Booking Calendar version 4.0. This vulnerability allows an attacker to execute remote code due to inadequate input validation in the Languages section, specifically within the Labels any parameters field in System Options, which is used to generate CSV files.
Exploitation of this vulnerability could lead to arbitrary code execution on the server where the application is running.
To reproduce this vulnerability, log into the application and navigate to the Options Menu. Click on 'Language' and then select the 'Labels' section. In any field, enter a payload designed for CSV injection. After injecting the payload, go to the 'Import/Export' section and click 'Export'. Open the exported file on your system to see the effects of the CSV injection.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.