CVE-2023-53877: Phpjabbers Bus Reservation System

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

Affected products

  • Phpjabbers Bus Reservation System: version 1.1 only

Published 2025-12-15. Last modified 2026-06-17.