Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2023-48837

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48836

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48835

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Attacker Value
Unknown

CVE-2023-48834

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-40764

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-40754

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.