PT-2025-4062 · Unknown · Code-Projects Job Recruitment
1337Gu
+1
·
Published
2025-01-29
·
Updated
2025-02-11
·
CVE-2025-0806
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
code-projects Job Recruitment version 1.0
Description
This issue affects some unknown processing of the file call job search ajax.php. The manipulation of the
job type argument leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
code-projects Job Recruitment version 1.0 should apply a patch or update to fix the cross-site scripting issue in the call job search ajax.php file, specifically securing the
job type argument to prevent remote attacks.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Code-Projects Job Recruitment