PT-2020-19480 · Simplejobscript.Com · Sjs
Gwen001
·
Published
2020-01-21
·
Updated
2024-02-14
·
CVE-2020-7229
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simplejobscript.com SJS versions prior to 1.65
Description
An issue was discovered in Simplejobscript.com SJS. There is unauthenticated SQL injection via the search engine, specifically through the
landing location parameter in the countSearchedJobs() function, located in the lib/class.Job.php file.Recommendations
For versions prior to 1.65, update to version 1.65 or later to resolve the issue. As a temporary workaround, consider restricting access to the search engine or disabling the
countSearchedJobs() function until a patch is available. Avoid using the landing location parameter in the affected search engine endpoint until the issue is resolved.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sjs