SQL Injection Vulnerability in Code-Projects Job Recruitment Product
CVE-2024-11076
5.3MEDIUM
Summary
A security vulnerability has been identified in the Code-Projects Job Recruitment product, specifically in the processing of the /activation.php file. This vulnerability arises from improper handling of the e_hash argument, which opens the door for SQL injection attacks. Remote attackers could exploit this weakness, potentially leading to unauthorized access to sensitive data and backend systems. The public disclosure of this issue emphasizes the importance of immediate mitigation strategies and updates to safeguard against potential exploitation.
Affected Version(s)
Job Recruitment 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Credit
李腾
谢亚轩
刘芮彤
UnrealDawn (VulDB User)
UnrealDawn (VulDB User)
falling-snow (VulDB User)