PT-2024-17834 · Code Projects · Code-Projects Job Recruitment

Unrealdawn

·

Published

2024-12-26

·

Updated

2024-12-31

·

CVE-2024-12963

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Job Recruitment version 1.0
Description A critical issue was found in the add xp function of the file / parse/ all edits.php. The manipulation of the job company argument leads to SQL injection. This issue can be exploited remotely. Other parameters might also be affected.
Recommendations For code-projects Job Recruitment version 1.0, update to the latest version and implement proper input sanitization to prevent SQL injection. As a temporary workaround, consider restricting access to the add xp function in the / parse/ all edits.php file until a patch is available. Additionally, avoid using the job company argument in the affected function until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-12963

Affected Products

Code-Projects Job Recruitment