CVE-2017-14838

HIGH

TeamWork Job Links - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-14838. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit describes an arbitrary file upload vulnerability in Job Links - Complete Job Management Script. The vulnerable code allows authenticated users to upload arbitrary files by manipulating the avatar or cover image upload functionality.

Description

TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.

Exploits (1)

exploitdb WRITEUP
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/42795

The exploit describes an arbitrary file upload vulnerability in Job Links - Complete Job Management Script. The vulnerable code allows authenticated users to upload arbitrary files by manipulating the avatar or cover image upload functionality.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Job Links - Complete Job Management Script
Auth required
Prerequisites: Authenticated user access · Access to the profile change functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42795/

Scores

CVSS v3 8.8
EPSS 0.0352
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
teamworktec/job_links
Published Sep 28, 2017
Tracked Since Feb 18, 2026