PT-2024-16779 · Unknown · Code-Projects Job Recruitment

Li_12138

·

Published

2024-11-12

·

Updated

2024-11-15

·

CVE-2024-11127

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Job Recruitment version 1.0
Description A critical issue has been found in the code-projects Job Recruitment software. The problem affects an unknown functionality of the file admin.php. The manipulation of the userid argument leads to SQL injection. This issue can be exploited remotely. There is a potential for unauthenticated remote code execution via the userid in admin.php.
Recommendations For code-projects Job Recruitment version 1.0, patch immediately and review logs for signs of exploitation. As a temporary workaround, consider restricting access to the admin.php file to minimize the risk of exploitation. Avoid using the userid argument in the affected functionality until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-11127

Affected Products

Code-Projects Job Recruitment