This issue was fixed in version 4.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Title | Authenticated SQL Injection in PHP Poll Script | |
| First Time appeared |
Php Jabbers
Php Jabbers php Poll Script |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:php_jabbers:php_poll_script:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Php Jabbers
Php Jabbers php Poll Script |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-31T11:40:53.781Z
Reserved: 2026-05-15T13:52:51.435Z
Link: CVE-2026-46593
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')