Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14838. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit describes an arbitrary file upload vulnerability in Job Links - Complete Job Management Script. The vulnerable code allows authenticated users to upload arbitrary files by manipulating the avatar or cover image upload functionality.
Description
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
Exploits (1)
exploitdb
WRITEUP
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/42795
The exploit describes an arbitrary file upload vulnerability in Job Links - Complete Job Management Script. The vulnerable code allows authenticated users to upload arbitrary files by manipulating the avatar or cover image upload functionality.
Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:
Job Links - Complete Job Management Script
Auth required
Prerequisites:
Authenticated user access · Access to the profile change functionality
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/42795/
Scores
CVSS v3
8.8
EPSS
0.0352
EPSS Percentile
87.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
teamworktec/job_links
Published
Sep 28, 2017
Tracked Since
Feb 18, 2026