
🚨High - PHP Jabbers Scripts Authenticated SQLi via ORDER BY Sort Params (CVE-2025-67650) Multiple PHP Jabbers PHP scripts fail to neutralize user-controlled sort parameters passed into SQL sorting/ORDER BY logic, enabling authenticated SQL injection against the backend database. Instances running at or above the vendor “lessThan” fixed thresholds are not affected. 👉Affected: PHP Jabbers scripts (versions below vendor fixed lessThan thresholds)
Post summary
The text announces a high‑severity authenticated SQL injection vulnerability (CVE‑2025‑67650) affecting older PHP Jabbers scripts, noting that vendor‑fixed thresholds mitigate the issue.
