← Vulnerability feed

Vulnerability record · CVE-2023-51331 · published 20 February 2025

CVE-2023-51331: Phpjabbers cleaning business software code injection vulnerability

Phpjabbers · Cleaning Business Software

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

6.5 CVSS 3.1 Medium EPSS 0.51% · top 58.5% CWE-94 · Code injection
6.5CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-51331 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36140Phpjabbers cleaning business software missing authorization vulnerabilityIn PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.EPSS 0.53%9.8CVE-2023-36139Phpjabbers cleaning business software insufficient verification of data authenticity vulnerabilityIn PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote…EPSS 0.45%6.5CVE-2023-51326Phpjabbers cleaning business software authentication bypass by spoofing vulnerabilityA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount o…EPSS 0.47%6.5CVE-2023-51327Phpjabbers cleaning business software authentication bypass by spoofing vulnerabilityA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount o…EPSS 0.47%6.1CVE-2023-36138Phpjabbers cleaning business software cross-site scripting vulnerabilityPHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.EPSS 0.44%6.1CVE-2023-4115Phpjabbers cleaning business software cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php…EPSS 8.4%5.4CVE-2023-51328Phpjabbers cleaning business software cross-site scripting vulnerabilityPHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.EPSS 0.38%5.3CVE-2023-36141Phpjabbers cleaning business software vulnerabilityUser enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2023-51331), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.