Required CVE Record Information
Description
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. This vulnerability affects unknown code of the file /_parse/load_user-profile.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Multiple parameters might be affected.
CVSS 4 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.1 | MEDIUM | 4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
3.5 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
3.5 | LOW | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
4.0 | — | 2.0 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Credits
- JunFeiGu (VulDB User) reporter
References 5 Total
- vuldb.com: VDB-295096 | code-projects Job Recruitment load_user-profile.php cross site scripting vdb-entry
- vuldb.com: VDB-295096 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- vuldb.com: Submit #496670 | code-projects job-recruitment-in-php 1/0 php Cross Site Scripting third-party-advisory
- https://github.com/1337g/CVE-2025-X/blob/main/job-recruitment-load_applicants-xss.pdf related
- https://code-projects.org/ product