PT-2020-19480 · Simplejobscript.Com · Sjs

Gwen001

·

Published

2020-01-21

·

Updated

2024-02-14

·

CVE-2020-7229

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simplejobscript.com SJS versions prior to 1.65
Description An issue was discovered in Simplejobscript.com SJS. There is unauthenticated SQL injection via the search engine, specifically through the landing location parameter in the countSearchedJobs() function, located in the lib/class.Job.php file.
Recommendations For versions prior to 1.65, update to version 1.65 or later to resolve the issue. As a temporary workaround, consider restricting access to the search engine or disabling the countSearchedJobs() function until a patch is available. Avoid using the landing location parameter in the affected search engine endpoint until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-7229

Affected Products

Sjs