CVE-2017-9603
HIGHWP Jobs < 1.4 - Authenticated SQL Injection via jobid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9603. PoCs published by Dimitrios Tsagkarakis.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the WordPress WP Jobs plugin before version 1.5. The PoC shows how an authenticated user can execute arbitrary SQL commands via the 'jobid' parameter in the edit.php page.
Description
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the WordPress WP Jobs plugin before version 1.5. The PoC shows how an authenticated user can execute arbitrary SQL commands via the 'jobid' parameter in the edit.php page.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H