CVE-2025-67649
published 2026-07-31CVE-2025-67649: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters…
PriorityP259critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.27%
19.5th percentile
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| php_jabbers | car_rental_script | < 4.1 | 4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script .
ghsa_unreviewed·2026-07-31
CVE-2025-67649 [CRITICAL] CWE-89 A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script .
A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks.
This issue was fixed in version 4.1.
VulDB
PHP Jabbers Car Rental Script up to 4.0 sql injection
vuldb·2026-07-31·CVSS 9.3
CVE-2025-67649 [CRITICAL] PHP Jabbers Car Rental Script up to 4.0 sql injection
A vulnerability described as critical has been identified in PHP Jabbers Car Rental Script up to 4.0. This affects an unknown part. The manipulation results in sql injection.
This vulnerability was named CVE-2025-67649. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-31
Published