SQL Injection Vulnerability in Campcodes Online Job Finder System
CVE-2024-2675
Key Information:
- Vendor
- Campcodes
- Status
- Vendor
- CVE Published:
- 20 March 2024
Badges
Summary
A serious SQL injection vulnerability has been identified in the Campcodes Online Job Finder System version 1.0. This flaw affects the processing of the file located at /admin/company/index.php. By manipulating the 'id' parameter, an attacker can execute arbitrary SQL queries to the database remotely, potentially allowing them access to sensitive data. Given the nature of this vulnerability, it poses significant risks for systems utilizing this software, especially as it has already been publicly disclosed, increasing its exploitability. Prompt action is recommended to mitigate this security threat.
Affected Version(s)
Online Job Finder System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved