Impact
The vulnerability allows an attacker to inject malicious script into responses returned by the file /Admin/DetailJob.php. By manipulating parameters that are not properly sanitized, an attacker can create payloads that will execute in the victim’s browser when the page is viewed. The impact is limited to what can be performed within the victim’s session, such as session hijacking, cookie theft or phishing, but it does not compromise the server directly. The weakness aligns with CWE‑79 and CWE‑94 for unfiltered input rendering.
Affected Systems
The affected product is code‑projects Online Job Portal version 1.0. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Because the description states the exploit can be performed remotely, an attacker can forge a request to the vulnerable endpoint from a malicious web page or by embedding a crafted URL in an email or message. No local privilege or complex prerequisites are required.
OpenCVE Enrichment