Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2025-12928: SQL Injection in code-projects Online Job Search Engine

0
Medium
VulnerabilityCVE-2025-12928cvecve-2025-12928
Published: Mon Nov 10 2025 (11/10/2025, 03:02:06 UTC)
Source: CVE Database V5
Vendor/Project: code-projects
Product: Online Job Search Engine

Description

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

AI-Powered Analysis

AILast updated: 11/17/2025, 04:49:07 UTC

Technical Analysis

CVE-2025-12928 is an SQL Injection vulnerability affecting the code-projects Online Job Search Engine version 1.0. The vulnerability resides in the /login.php script, where the username or phone parameters are improperly sanitized, allowing attackers to inject malicious SQL code. This injection flaw enables remote attackers to execute arbitrary SQL queries on the backend database without requiring authentication or user interaction. The vulnerability is exploitable over the network, making it accessible to any attacker who can reach the login endpoint. The CVSS 4.0 score of 6.9 reflects a medium severity, considering the attack vector is network-based with low complexity and no privileges or user interaction needed, but with limited impact on confidentiality, integrity, and availability. The exploit code has been publicly disclosed, increasing the risk of exploitation. The lack of official patches or updates means organizations must implement immediate mitigations. The vulnerability could allow attackers to bypass authentication, extract sensitive user data, or modify database contents, potentially leading to data breaches or service disruption. This is particularly concerning for organizations relying on this job search engine to manage user credentials and personal information. The vulnerability highlights the critical need for secure coding practices such as input validation and use of prepared statements to prevent SQL injection attacks.

Potential Impact

For European organizations using the affected Online Job Search Engine, this vulnerability poses a significant risk to the confidentiality and integrity of user data, including personal and login information. Exploitation could lead to unauthorized access to sensitive data, data leakage, or unauthorized modifications, undermining trust and potentially violating GDPR requirements. Service availability could also be impacted if attackers manipulate the database to disrupt operations. The public availability of exploit code increases the likelihood of attacks, especially targeting organizations that have not applied mitigations. Given the widespread use of online job platforms in Europe and the sensitivity of employment-related data, this vulnerability could have reputational and regulatory consequences. Organizations in sectors such as recruitment, human resources, and employment services are particularly at risk. The vulnerability's remote exploitability without authentication means attackers can operate from anywhere, increasing the threat landscape for European entities.

Mitigation Recommendations

Organizations should immediately implement input validation and sanitization on all user-supplied data, especially the username and phone parameters in the /login.php script. Employing parameterized queries or prepared statements is critical to prevent SQL injection. If possible, upgrade to a patched version of the software once available or apply vendor-provided fixes. In the absence of official patches, consider deploying web application firewalls (WAFs) with rules to detect and block SQL injection attempts targeting the login endpoint. Conduct thorough code reviews and security testing to identify and remediate similar injection flaws elsewhere in the application. Monitor logs for suspicious login attempts or anomalous database queries indicative of exploitation attempts. Additionally, restrict database user permissions to the minimum necessary to limit the impact of any successful injection. Educate development teams on secure coding practices to prevent recurrence. Finally, ensure regular backups of databases to enable recovery in case of data corruption or loss.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulDB
Date Reserved
2025-11-09T12:48:02.829Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 69115ed4b9239aa3908085ae

Added to database: 11/10/2025, 3:41:08 AM

Last enriched: 11/17/2025, 4:49:07 AM

Last updated: 12/23/2025, 5:49:57 PM

Views: 63

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats