Description
A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of the argument fname/lname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Es wurde eine problematische Schwachstelle in code-projects Job Recruitment 1.0 ausgemacht. Hiervon betroffen ist die Funktion fln_update der Datei /_parse/_all_edits.php. Dank Manipulation des Arguments fname/lname mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
| 2024-12-26: | Advisory disclosed |
| 2024-12-26: | VulDB entry created |
| 2024-12-26: | VulDB entry last update |
Credits
AceChestNut (VulDB User)
References
vuldb.com/?id.289356 (VDB-289356 | code-projects Job Recruitment _all_edits.php fln_update cross site scripting)
vuldb.com/?ctiid.289356 (VDB-289356 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.469181 (Submit #469181 | code-projects job-recruitmen-php 0/1 Cross Site Scripting)
github.com/705298066/cve/blob/main/xss-2.md
code-projects.org/