What is CVE-2025-67650?
An authenticated SQL injection vulnerability has been found in multiple PHP Jabbers scripts. Improper neutralization of user input in parameters responsible for sorting functions allows an authenticated attacker to perform SQL injection attacks. Updating to the latest version released by the vendor is recommended.
Azərbaycanca: PHP Jabbers skriptlərində autentifikasiya olunmuş SQL injection zəifliyi aşkarlanıb. Sıralama funksiyalarına məsul parametrlərə daxil edilən məlumatların düzgün neytrallaşdırılmaması səbəbindən autentifikasiya olunmuş istifadəçi SQL Injection hücumları həyata keçirə bilər. Tərtibatçı tərəfindən buraxılmış son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: PHP Jabbers
FAQ2
Can only authenticated users exploit the SQL injection vulnerability found in PHP Jabbers scripts, or can unauthenticated individuals also attack?
Only authenticated users can perform these SQL injection attacks.
What function in PHP Jabbers scripts is this SQL injection vulnerability related to?
The vulnerability is related to improper neutralization of user input in parameters responsible for sorting functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.