CVE-2025-67649 CRITICAL

CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script

Vendor Php Jabbers
Product Car Rental Script
Weakness CWE-89 · SQLi
Published July 31, 2026
Last update July 31, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1.

Key dates

02Disclosure timeline

July 31, 2026 CVE published