SQL Injection Vulnerability in Code-Projects Job Recruitment Platform
CVE-2024-12978
Key Information:
- Vendor
- Code-projects
- Status
- Vendor
- CVE Published:
- 27 December 2024
Badges
Summary
A significant security flaw has been identified in the Code-Projects Job Recruitment 1.0 application, specifically in the function responsible for handling user requests in the file /_parse/_all_edits.php. This vulnerability arises from improper handling of the parameters 'jid' and 'limit', allowing an attacker to perform SQL injection attacks. By manipulating these parameters, a remote attacker could potentially execute unauthorized SQL commands, leading to exposure of sensitive data or even full compromise of the application. This issue has been made public, and developers are advised to secure their systems against potential exploitation.
Affected Version(s)
Job Recruitment 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved