← Vulnerability feed

Vulnerability record · CVE-2019-25498 · published 4 March 2026

CVE-2019-25498: Simplejobscript sql injection vulnerability

Simplejobscript · Simplejobscript

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information.

8.8 CVSS 4.0 High EPSS 0.37% · top 72.1% CWE-89 · SQL injection
8.8CVSS 4.0 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25498 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8645Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. …EPSS 1.8%9.8CVE-2020-8440Simplejobscript unrestricted file upload vulnerabilitycontrollers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a r…EPSS 2.8%9.8CVE-2020-7229Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landin…EPSS 1.5%8.8CVE-2019-25499Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.45%8.8CVE-2019-25500Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.29%8.8CVE-2019-25501Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code throug…EPSS 0.34%5.1CVE-2019-25502Simplejobscript cross-site scripting vulnerabilitySimple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the…EPSS 0.25%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2019-25498), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.