CVE-2025-67651 MEDIUM

CVE-2025-67651: CSRF in PHP Jabbers scripts

Vendor Php Jabbers
Product Appointment Scheduler
Weakness CWE-352 · CSRF
Published July 31, 2026
Last update July 31, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating new admin accounts. This issue was fixed in the versions specified in the affected products list.

Key dates

02Disclosure timeline

July 31, 2026 CVE published

Related vulnerabilities

04Related CVE