Impact
The weakness lies in the JobSeekerInsert.php function of Online Job Portal 1.0, where manipulation of the txtFile parameter allows an attacker to upload any file without restriction. This is an instance of CWE-434: Unrestricted Upload of File with Dangerous Type and also represents CWE-284: Improper Access Control over the upload endpoint. The CVSS score of 6.9 indicates moderate severity, and the presence of a public exploit raises the risk of application integrity loss and potential remote code execution when executable files are uploaded.
Affected Systems
Affected are users running the code-projects Online Job Portal version 1.0, specifically those using the JobSeekerInsert.php functionality. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score of <1% suggests a low probability of exploitation, and this vulnerability is not listed in KEV. Although the attack can be executed remotely, specific exploitation details are not provided and therefore are inferred, not guaranteed. The fact that a public exploit is available indicates that the opportunity for real-world compromise exists.
OpenCVE Enrichment