← Vulnerability feed

Vulnerability record · CVE-2020-8440 · published 31 January 2020

CVE-2020-8440: Simplejobscript unrestricted file upload vulnerability

Simplejobscript · Simplejobscript

controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.

9.8 CVSS 3.1 Critical EPSS 2.8% · top 14.0% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8440 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8645Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. …EPSS 1.8%9.8CVE-2020-7229Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landin…EPSS 1.5%8.8CVE-2019-25498Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.37%8.8CVE-2019-25499Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.45%8.8CVE-2019-25500Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.29%8.8CVE-2019-25501Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code throug…EPSS 0.34%5.1CVE-2019-25502Simplejobscript cross-site scripting vulnerabilitySimple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the…EPSS 0.25%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8440), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.