SQL Injection Vulnerability in itsourcecode Open Source Job Portal Product
CVE-2025-11041
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 26 September 2025
Badges
What is CVE-2025-11041?
A SQL injection vulnerability exists in the itsourcecode Open Source Job Portal version 1.0, specifically affecting the file located at /admin/user/index.php?view=edit. The flaw arises from improper handling of user-supplied input in the 'ID' argument, enabling attackers to execute arbitrary SQL commands. This vulnerability can be exploited remotely, posing a significant risk to the integrity of the application's database. It is crucial for users to implement timely patches and follow security best practices to mitigate this risk.
Affected Version(s)
Open Source Job Portal 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved