PT-2025-41604 · Unknown · Online Job Search Engine

Xupeng

·

Published

2025-10-10

·

Updated

2025-10-20

·

CVE-2025-11584

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Job Search Engine version 1.0
Description A SQL injection issue exists in the Online Job Search Engine 1.0, specifically within the /searchjob.php file. The txtspecialization parameter is susceptible to manipulation, allowing for the execution of arbitrary SQL commands. This vulnerability is remotely exploitable and does not require authentication. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-11584

Affected Products

Online Job Search Engine