CVE-2019-25499
HIGHsimplejobscript < 1.66 - Unauthenticated SQL Injection via job_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25499. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter.
Description
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N