← Vulnerability feed

Vulnerability record · CVE-2019-25499 · published 4 March 2026

CVE-2019-25499: Simplejobscript sql injection vulnerability

Simplejobscript · Simplejobscript

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.

8.8 CVSS 4.0 High EPSS 0.45% · top 63.1% CWE-89 · SQL injection
8.8CVSS 4.0 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8645Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. …EPSS 1.8%9.8CVE-2020-8440Simplejobscript unrestricted file upload vulnerabilitycontrollers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a r…EPSS 2.8%9.8CVE-2020-7229Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landin…EPSS 1.5%8.8CVE-2019-25498Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.37%8.8CVE-2019-25500Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.29%8.8CVE-2019-25501Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code throug…EPSS 0.34%5.1CVE-2019-25502Simplejobscript cross-site scripting vulnerabilitySimple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the…EPSS 0.25%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2019-25499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.