First published: Fri Dec 27 2024(Updated: )
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the function cn_update of the file /_parse/_all_edits.php. The manipulation of the argument cname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Code-Projects Job Recruitment | ||
Anisha Job Recruitment | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12979 is classified as a problematic vulnerability affecting the Job Recruitment 1.0 software.
CVE-2024-12979 allows for cross-site scripting through manipulation of the cname argument in the cn_update function.
Yes, CVE-2024-12979 can be exploited remotely by attackers.
To fix CVE-2024-12979, ensure that input validation and sanitization are implemented for the cname argument in the affected code.
CVE-2024-12979 affects Job Recruitment version 1.0 as developed by Code-Projects.