CVE-2024-12966: code-projects Job Recruitment _all_edits.php cn_update sql injection
A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function cnupdate of the file /parse/alledits.php. The manipulation of the argument cname/url leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12966?
CVE-2024-12966 has been rated as critical due to its potential for remote SQL injection.
How does CVE-2024-12966 affect the Job Recruitment software?
CVE-2024-12966 affects the function cn_update in the file /_parse/_all_edits.php, allowing for manipulation of the cname/url argument.
What type of attack can be initiated through CVE-2024-12966?
CVE-2024-12966 allows for remote SQL injection attacks, which can compromise the database.
Who is affected by CVE-2024-12966?
Users and administrators of Code-Projects Job Recruitment version 1.0 are vulnerable to CVE-2024-12966.
What steps should I take to remediate CVE-2024-12966?
To fix CVE-2024-12966, it is advised to sanitize inputs thoroughly and apply security patches provided by the vendor.