CVE-2026-7028

MEDIUM

CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-7028. PoCs published by Xmyronn.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7028, an SQL injection vulnerability in CodeAstro's Online Job Portal. It includes a step-by-step proof of concept demonstrating how an authenticated attacker can delete all job records by injecting malicious input into the 'id' parameter.

Description

A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

Exploits (1)

nomisec WRITEUP
by Xmyronn · poc
https://github.com/Xmyronn/CVE-2026-7028-SQLI

This repository provides a detailed technical analysis of CVE-2026-7028, an SQL injection vulnerability in CodeAstro's Online Job Portal. It includes a step-by-step proof of concept demonstrating how an authenticated attacker can delete all job records by injecting malicious input into the 'id' parameter.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: CodeAstro Online Job Portal Project in PHP MySQL 1.0
Auth required
Prerequisites: Admin access to the target application
devstral-2 · analyzed Apr 26, 2026 Full analysis →

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-359608 | CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
https://vuldb.com/vuln/359608
Signature, Permissions Required signature permissions-required
VDB-359608 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/359608/cti
Third Party Advisory third-party-advisory
Submit #797969 | CodeAstro Online Job Portal Project in PHP MySQL 1.0 SQL Injection
https://vuldb.com/submit/797969
Product product
https://codeastro.com/

Scores

CVSS v3 4.7
EPSS 0.0031
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
CodeAstro/Online Job Portal 1.0
Published Apr 26, 2026
Tracked Since Apr 26, 2026