First published: Wed Feb 12 2025(Updated: )
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Code-Projects Job Recruitment | =1.0 | |
Anisha Job Recruitment | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1190 has been classified as problematic due to its potential for cross site scripting exploits.
To fix CVE-2025-1190, ensure that input validation and output encoding are implemented in the affected file, /_parse/load_user-profile.php.
Attacks leveraging CVE-2025-1190 can include cross site scripting, which may allow attackers to inject malicious scripts into web pages viewed by users.
CVE-2025-1190 specifically affects version 1.0 of the Code-Projects Job Recruitment software.
Yes, CVE-2025-1190 can be exploited remotely, allowing attackers to manipulate the affected file without physical access.