Vulnerabilities
Vulnerable Software
An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.
CVSS Score
9.8
EPSS Score
0.005
Published
2020-02-07
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.
CVSS Score
9.8
EPSS Score
0.033
Published
2020-01-31


Contact Us

Shodan ® - All rights reserved