Cross-Site Scripting Vulnerability in Code-Projects Job Recruitment Software
CVE-2024-12979
Key Information:
- Vendor
- Code-projects
- Status
- Job Recruitment
- Vendor
- CVE Published:
- 27 December 2024
Badges
Summary
A cross-site scripting (XSS) vulnerability has been identified in the Job Recruitment software developed by Code-Projects, specifically within the cn_update function found in the _all_edits.php file. This vulnerability can be exploited by manipulating the 'cname' argument, allowing attackers to inject malicious scripts. The exploit can be executed remotely, posing significant risks to the security of user data and application integrity. It is critical for users of the affected product to implement security measures to mitigate the potential for exploitation.
Affected Version(s)
Job Recruitment 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved