← Vulnerability feed

Vulnerability record · CVE-2014-10001 · published 13 January 2015

CVE-2014-10001: Phpjabbers appointment scheduler cross-site request forgery vulnerability

Phpjabbers · Appointment Scheduler

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.

6.8 CVSS 2.0 Medium EPSS 2.3% · top 17.7% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-10001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-48841Phpjabbers appointment scheduler injection vulnerabilityAppointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.EPSS 1.2%7.5CVE-2023-48840Phpjabbers appointment scheduler uncontrolled resource consumption vulnerabilityA lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.EPSS 1.1%7.5CVE-2023-36127Phpjabbers appointment scheduler observable discrepancy vulnerabilityUser enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages coul…EPSS 0.59%6.1CVE-2023-36126Phpjabbers appointment scheduler cross-site scripting vulnerabilityThere is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0EPSS 0.38%5.4CVE-2023-48838Phpjabbers appointment scheduler cross-site scripting vulnerabilityAppointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.EPSS 0.46%5.4CVE-2023-48839Phpjabbers appointment scheduler cross-site scripting vulnerabilityAppointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_cod…EPSS 0.42%5.0CVE-2014-10010Phpjabbers appointment scheduler path traversal vulnerabilityDirectory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the i…EPSS 7.7%9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2014-10001), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.