CVE-2024-12968: code-projects Job Recruitment _all_edits.php edit_jobpost sql injection
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is the function editjobpost of the file /parse/alledits.php. The manipulation of the argument jobtype leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12968?
CVE-2024-12968 is classified as a critical vulnerability.
How does CVE-2024-12968 affect the Job Recruitment application?
CVE-2024-12968 affects the function edit_jobpost in the file /_parse/_all_edits.php, leading to SQL injection vulnerabilities.
What type of attack can be executed with CVE-2024-12968?
An attacker can launch a remote SQL injection attack exploiting CVE-2024-12968.
How can I fix CVE-2024-12968?
The fix for CVE-2024-12968 involves implementing proper input validation and parameterized queries in the affected function.
Which software versions are affected by CVE-2024-12968?
CVE-2024-12968 impacts Code-Projects Job Recruitment version 1.0.