CVE-2025-1162: code-projects Job Recruitment load\_user-profile.php sql injection
Published Feb 10, 2025
·Updated
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\parse/load\user-profile.php. The manipulation of the argument userhash leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Code-projects Job Recruitment
Anisha Job Recruitment=1.0
Event History
Feb 10, 2025
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1162?
CVE-2025-1162 is classified as a critical vulnerability.
2
What happens if CVE-2025-1162 is exploited?
Exploitation of CVE-2025-1162 through SQL injection can allow remote attackers to manipulate the database.
3
How do I fix CVE-2025-1162?
To fix CVE-2025-1162, sanitize and validate the 'userhash' input to prevent SQL injection.
4
Which software is affected by CVE-2025-1162?
CVE-2025-1162 affects the code-projects Job Recruitment version 1.0.
5
Is CVE-2025-1162 a remote exploit?
Yes, CVE-2025-1162 can be exploited remotely.