CVE-2024-12962: code-projects Job Recruitment _all_edits.php sql injection
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /parse/alledits.php. The manipulation of the argument skillset leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12962?
CVE-2024-12962 is classified as a critical vulnerability due to its potential for SQL injection.
How does CVE-2024-12962 exploit the system?
CVE-2024-12962 exploits the system by manipulating the argument skillset in the file /_parse/_all_edits.php.
Which software versions are affected by CVE-2024-12962?
CVE-2024-12962 affects version 1.0 of the Job Recruitment software by Code-Projects and Anisha.
How do I fix CVE-2024-12962?
To fix CVE-2024-12962, sanitize and validate user inputs to prevent SQL injection attacks.
Who is the vendor of the software affected by CVE-2024-12962?
The vendors of the affected software are Code-Projects and Anisha.