PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51416 | Exploit Third Party Advisory VDB Entry |
| https://www.phpjabbers.com/faq.php | Product |
| https://www.vulncheck.com/advisories/phpjabbers-simple-cms-sql-injection-via-column-parameter | Third Party Advisory |
Configurations
History
24 Dec 2025, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Phpjabbers
Phpjabbers simple Cms |
|
| CPE | cpe:2.3:a:phpjabbers:simple_cms:5.0:*:*:*:*:*:*:* | |
| References | () https://www.exploit-db.com/exploits/51416 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.phpjabbers.com/faq.php - Product | |
| References | () https://www.vulncheck.com/advisories/phpjabbers-simple-cms-sql-injection-via-column-parameter - Third Party Advisory |
17 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 23:15
Updated : 2025-12-24 18:03
NVD link : CVE-2023-53926
Mitre link : CVE-2023-53926
CVE.ORG link : CVE-2023-53926
JSON object : View
Products Affected
phpjabbers
- simple_cms
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
