Phpgurukul Job Portal vulnerabilities
12 known vulnerabilities affecting phpgurukul/job_portal.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-8469HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8469 [CRITICAL] CWE-89 CVE-2024-8469: SQL injection vulnerability, by which an attacker could send a specially designed query through id p
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8468HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8468 [CRITICAL] CWE-89 CVE-2024-8468: SQL injection vulnerability, by which an attacker could send a specially designed query through sear
SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8464HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8464 [CRITICAL] CWE-89 CVE-2024-8464: SQL injection vulnerability, by which an attacker could send a specially designed query through JOBR
SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8470HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8470 [CRITICAL] CWE-89 CVE-2024-8470: SQL injection vulnerability, by which an attacker could send a specially designed query through CATE
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8467HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8467 [CRITICAL] CWE-89 CVE-2024-8467: SQL injection vulnerability, by which an attacker could send a specially designed query through id p
SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8463HIGHCVSS 8.8v1.02024-09-05
CVE-2024-8463 [CRITICAL] CWE-434 CVE-2024-8463: File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which
File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.
cvelistv5nvd
CVE-2024-8466HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8466 [CRITICAL] CWE-89 CVE-2024-8466: SQL injection vulnerability, by which an attacker could send a specially designed query through CATE
SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8465HIGHCVSS 7.5v1.02024-09-05
CVE-2024-8465 [CRITICAL] CWE-89 CVE-2024-8465: SQL injection vulnerability, by which an attacker could send a specially designed query through user
SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.
cvelistv5nvd
CVE-2024-8473MEDIUMCVSS 6.1v1.02024-09-05
CVE-2024-8473 [MEDIUM] CWE-79 CVE-2024-8473: Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypte
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.
cvelistv5nvd
CVE-2024-8472MEDIUMCVSS 6.1v1.02024-09-05
CVE-2024-8472 [MEDIUM] CWE-79 CVE-2024-8472: Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypte
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.
cvelistv5nvd
CVE-2024-8471MEDIUMCVSS 6.1v1.02024-09-05
CVE-2024-8471 [MEDIUM] CWE-79 CVE-2024-8471: Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypte
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.
cvelistv5nvd
CVE-2020-10225CRITICALCVSS 9.8v1.02020-03-08
CVE-2020-10225 [CRITICAL] CWE-434 CVE-2020-10225: An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.
nvd