A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of the argument fname/lname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Dec 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of the argument fname/lname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | code-projects Job Recruitment _all_edits.php fln_update sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-26T21:31:05.327Z
Updated: 2024-12-26T21:31:05.327Z
Reserved: 2024-12-26T07:57:26.041Z
Link: CVE-2024-12967
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-26T22:15:09.487
Modified: 2024-12-26T22:15:09.487
Link: CVE-2024-12967
Redhat
No data.