The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-28928 The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:22:25.494Z

Reserved: 2021-10-04T00:00:00

Link: CVE-2021-41931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-17T12:15:17.090

Modified: 2024-11-21T06:26:58.253

Link: CVE-2021-41931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses