CVE-2024-12979
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 27, 2024
Updated: Feb 18, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2024-12979 is a newly disclosed vulnerability affecting the code-projects Job Recruitment 1.0. The issue lies in the function cn_update of the file /_parse/_all_edits.php, where the argument cname is susceptible to cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability remotely by manipulating the cname parameter, potentially injecting malicious scripts. The exploit has been made public, increasing the risk of successful attacks. Other parameters in the function might also be susceptible to similar attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Job Recruitment
Affected Vendors
- Code Projects
- Anisha