Egavilan Media Resumes Management and Job Application Website Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Egavilan Media Resumes Management and Job Application Website version 1.0. This vulnerability allows remote attackers to inject arbitrary code into the application. The issue arises in the 'Apply For This Job' form, where injected scripts in the First and Last Name fields are executed when the application is accessed by an admin user.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.

Reproduction

To reproduce this vulnerability, navigate to the 'Apply For This Job' section of the website. Inject a script, such as a JavaScript alert, into the First Name and Last Name fields. After submitting the form, log in as an admin user. The injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
7.9
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.