Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25501. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes specific payloads for vulnerable parameters such as 'landing_location', 'job_id', 'employerid', and 'job_type_value[]'.
Description
Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code through the app_id parameter. Attackers can send POST requests to delete_application_ajax.php with crafted payloads to extract sensitive data, bypass authentication, or modify database contents.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes specific payloads for vulnerable parameters such as 'landing_location', 'job_id', 'employerid', and 'job_type_value[]'.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N