CVE-2024-12979

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Feb 18, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-12979 is a newly disclosed vulnerability affecting the code-projects Job Recruitment 1.0. The issue lies in the function cn_update of the file /_parse/_all_edits.php, where the argument cname is susceptible to cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability remotely by manipulating the cname parameter, potentially injecting malicious scripts. The exploit has been made public, increasing the risk of successful attacks. Other parameters in the function might also be susceptible to similar attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Job Recruitment

Affected Vendors

  • Code Projects
  • Anisha