NCrypted Jobgator SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in NCrypted Jobgator, allowing unauthenticated attackers to manipulate database queries. The vulnerability arises from the experience parameter, which can be exploited by sending POST requests to the agents Find-Jobs endpoint with maliciously crafted experience values. This exploitation could lead to the extraction of sensitive information from the database.
Impact
Exploitation of this vulnerability allows for unauthorized manipulation of database queries, potentially leading to the extraction of sensitive database information.
Reproduction
To reproduce this vulnerability, send a POST request to the agents Find-Jobs endpoint with the experience parameter injected with SQL code, such as '1" OR NOT 4365=4365#'. This payload exploits the SQL injection vulnerability by manipulating the SQL query processing.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
