CVE-2024-12979: code-projects Job Recruitment _all_edits.php cn_update cross site scripting
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the function cnupdate of the file /parse/alledits.php. The manipulation of the argument cname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12979?
CVE-2024-12979 is classified as a problematic vulnerability affecting the Job Recruitment 1.0 software.
How does CVE-2024-12979 affect the system?
CVE-2024-12979 allows for cross-site scripting through manipulation of the cname argument in the cn_update function.
Can CVE-2024-12979 be exploited remotely?
Yes, CVE-2024-12979 can be exploited remotely by attackers.
How do I fix CVE-2024-12979?
To fix CVE-2024-12979, ensure that input validation and sanitization are implemented for the cname argument in the affected code.
What versions of Job Recruitment are affected by CVE-2024-12979?
CVE-2024-12979 affects Job Recruitment version 1.0 as developed by Code-Projects.