Simplejobscript是Niteosoft开源的一个免费工作板软件。 Simplejobscript存在SQL注入漏洞,该漏洞源于employerid参数存在SQL注入,可能导致未经验证的攻击者操纵数据库查询并提取敏感数据或修改数据库内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| niteosoft | Simple Job Script | 1.66 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| niteosoft | Simple Job Script | 1.66 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-25501 | 8.2 HIGH | Simple Job Script SQL Injection via delete_application_ajax.php |
| CVE-2019-25498 | 8.2 HIGH | Simple Job Script SQL Injection via searched Endpoint |
| CVE-2019-25499 | 8.2 HIGH | Simple Job Script SQL Injection via get_job_applications_ajax.php |
| CVE-2019-25502 | 6.1 MEDIUM | Simple Job Script Cross-Site Scripting via job_type_value Parameter |
No comments yet