CVE-2019-25504
HIGHNCrypted Jobgator - Unauthenticated SQL Injection via Experience Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25504. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NCrypted Jobgator via the 'experience' POST parameter. The payload bypasses authentication by injecting a tautology (OR NOT 4365=4365) to manipulate the SQL query.
Description
NCrypted Jobgator contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the experience parameter. Attackers can send POST requests to the agents Find-Jobs endpoint with malicious experience values to extract sensitive database information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in NCrypted Jobgator via the 'experience' POST parameter. The payload bypasses authentication by injecting a tautology (OR NOT 4365=4365) to manipulate the SQL query.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N