CVE-2025-0168

Published Jan 1, 2025

Last updated 17 days ago

Overview

Description
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The manipulation of the argument person leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Source
cna@vuldb.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Secondary
Base score
6.3
Impact score
3.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity
MEDIUM

CVSS 2.0

Type
Secondary
Base score
6.5
Impact score
6.4
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:P/I:P/A:P

Weaknesses

cna@vuldb.com
CWE-74

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. 🚨 CVE-2025-0168: Vulnerabilidad de Inyección SQL en Job Recruitment 1.0 🔒 🛑 Nivel de Urgencia: Alto 📊 Puntuación CVSS: 7.1 Un fallo en el archivo / _parse/_feedback_system.php permite manipular el parámetro person, lo que podría ser para comprometer bases de datos. https:/

    @BanCERT_gt

    17 Jan 2025

    18 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-0168 is of course, the first CVE of 2025....

    @Tucketmaster

    2 Jan 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. vFeed's first CVE in 2025 CVE-2025-0168 A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0 /_parse/_feedback_system.php, leading to an SQL injection remotely CVSS3 base 6.3, Impact 6.4, Network vector https://t.co/IkHjojzbKU

    @vFeed_IO

    2 Jan 2025

    100 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Heyo 👋, here's the first published CVE of 2025. CVE-2025-0168. An SQLi in some job recruitment system.

    @byt3n33dl3

    2 Jan 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. First CVE of 2025: CVE-2025-0168 SQL Injection in code-projects Job Recruitment 1.0 https://t.co/Du8jd7dLq5 #vulmon #infosec

    @vulmoncom

    1 Jan 2025

    135 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. 🚨 CVE-2025-0168: Critical SQL Injection in Job Recruitment System 🚨 WIRE TOR - The Ethical Hacking Services A critical vulnerability has been identified in the Job Recruitment system by code-projects, affecting version 1.0. The flaw resides in the feedbacksystem.php. #hack htt

    @WireTor

    1 Jan 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-0168 A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /_parse/_feedback_system.php. The m… https://t.co/Vj1RTrwNEP

    @CVEnew

    1 Jan 2025

    1022 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes