CVE-2026-7028
MEDIUMCodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-7028. PoCs published by Xmyronn.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7028, an SQL injection vulnerability in CodeAstro's Online Job Portal. It includes a step-by-step proof of concept demonstrating how an authenticated attacker can delete all job records by injecting malicious input into the 'id' parameter.
Description
A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the component All Jobs Page. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-7028, an SQL injection vulnerability in CodeAstro's Online Job Portal. It includes a step-by-step proof of concept demonstrating how an authenticated attacker can delete all job records by injecting malicious input into the 'id' parameter.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L