PT-2020-20140 · Simplejobscript.Com · Sjs

Gwen001

·

Published

2020-01-31

·

Updated

2020-02-05

·

CVE-2020-8440

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simplejobscript.com SJS versions 1.66 and earlier
Description The issue allows for unauthenticated Remote Code Execution by uploading a PHP script as a resume, specifically affecting the controllers/page apply.php file.
Recommendations For versions 1.66 and earlier, consider disabling the resume upload feature in the controllers/page apply.php file until a patch is available. Restrict access to this file to minimize the risk of exploitation. Avoid using this feature until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8440

Affected Products

Sjs