code-projects Online Job Portal JobSeekerInsert.php unrestricted upload
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.9epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
code-projects · Online Job Portalpublic PoCs found — 1
cve_referencegithub.com/shihuizhang-dazhi/MY-CVE/issues/6unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.