PT-2024-9924 · Unknown · Code-Projects Job Recruitment

Acechestnut

·

Published

2024-12-26

·

Updated

2024-12-27

·

CVE-2024-12968

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: code-projects Job Recruitment version 1.0
Description: A critical vulnerability was found in the function edit jobpost of the file / parse/ all edits.php. The manipulation of the argument jobtype leads to SQL injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Recommendations: For code-projects Job Recruitment version 1.0, as a temporary workaround, consider disabling the edit jobpost function until a patch is available. Restrict access to the all edits.php file to minimize the risk of exploitation. Avoid using the parameter jobtype in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-00035
CVE-2024-12968

Affected Products

Code-Projects Job Recruitment