PT-2026-22956 · Unknown · Simple Job Script
Published
2026-03-04
·
Updated
2026-03-05
·
CVE-2019-25501
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Job Script (affected versions not specified)
Description
The software contains an SQL injection issue that allows manipulation of database queries through malicious SQL code. Attackers can exploit this by injecting code via the
app id parameter. Specifically, attackers can send POST requests to the ''delete application ajax.php'' endpoint with crafted payloads. This can lead to the extraction of sensitive data, bypassing authentication mechanisms, or modification of database contents.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Job Script