PHPJabbers Meeting Room Booking System
cpe:2.3:a:phpjabbers:meeting_room_booking_system:*:*:*:*:*:*:*
- 1.0
A CSV injection vulnerability has been identified in PHPJabbers Meeting Room Booking System version 1.0. This vulnerability allows an attacker to execute remote code due to inadequate input validation in the Languages section Labels any parameters field within System Options, which is utilized to generate CSV files.
Exploitation of this vulnerability could lead to arbitrary code execution on the server where the application is hosted.
To reproduce this vulnerability, log into the application and navigate to the Options Menu. Click on 'Language' and then select the 'Labels' section. Enter a CSV injection payload into any field. Afterward, go to the 'Import/Export' section, click on 'Export', and open the exported file on your system. The injected payload will be executed, demonstrating the CSV injection vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.