PT-2020-20251 · Simplejobscript.Com · Sjs

Gwen001

·

Published

2020-02-06

·

Updated

2020-02-12

·

CVE-2020-8645

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simplejobscript.com SJS versions 1.66 and earlier
Description An issue was discovered in the job applications search function, allowing for unauthenticated SQL injection. The job id parameter is vulnerable, and the issue is related to the getJobApplicationsByJobId() function in the lib/class.JobApplication.php file.
Recommendations For versions 1.66 and earlier, consider restricting access to the getJobApplicationsByJobId() function until a patch is available. Avoid using the job id parameter in the affected search function to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8645

Affected Products

Sjs