PHPJabbers Shared Asset Booking System CSV Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A CSV injection vulnerability has been identified in PHPJabbers Shared Asset Booking System version 1.0. This vulnerability allows an attacker to execute remote code due to inadequate input validation in the Languages section, specifically within the Labels parameters of System Options used to generate CSV files.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the server where the application is hosted.

Reproduction

To reproduce this vulnerability, log into the admin panel and navigate to the Options Menu. Click on 'Language' and then select the 'Labels' section. Insert a CSV injection payload into any field, then go to the 'Import/Export' section. Click 'Export' and open the exported file to execute the injected payload.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.