PHPJabbers Restaurant Booking System CSV Injection Vulnerability Allowing Remote Code Execution
Vulnerability
A CSV injection vulnerability has been identified in PHPJabbers Restaurant Booking System version 3.0. This vulnerability allows an attacker to execute remote code and arises from inadequate input validation in the Languages section, specifically within the Labels any parameters field in System Options, which is used to generate CSV files.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution on the server where the application is running.
Reproduction
To reproduce this vulnerability, log into the application and navigate to the Options Menu. Click on Language, then select the Labels section. Enter a CSV injection payload into any field and proceed to the Import/Export section. Click export and open the exported file to execute the injected payload.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
