SQL Injection Vulnerability in Code-Projects Job Recruitment Product
CVE-2024-11076

5.3MEDIUM

Key Information:

Vendor
CVE Published:
11 November 2024

Summary

A security vulnerability has been identified in the Code-Projects Job Recruitment product, specifically in the processing of the /activation.php file. This vulnerability arises from improper handling of the e_hash argument, which opens the door for SQL injection attacks. Remote attackers could exploit this weakness, potentially leading to unauthorized access to sensitive data and backend systems. The public disclosure of this issue emphasizes the importance of immediate mitigation strategies and updates to safeguard against potential exploitation.

Affected Version(s)

Job Recruitment 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

Credit

李腾
谢亚轩
刘芮彤
UnrealDawn (VulDB User)
UnrealDawn (VulDB User)
falling-snow (VulDB User)
.
CVE-2024-11076 : SQL Injection Vulnerability in Code-Projects Job Recruitment Product | SecurityVulnerability.io