Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25500. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter, confirming the vulnerabilities are exploitable.
Description
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the employerid parameter. Attackers can send POST requests to the register-recruiters endpoint with time-based SQL injection payloads to extract sensitive data or modify database contents.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter, confirming the vulnerabilities are exploitable.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N