High severity8.2NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2019-25499
CVE-2019-25499
Description
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the job_id parameter. Attackers can send POST requests to get_job_applications_ajax.php with malicious job_id values to bypass authentication, extract sensitive data, or modify database contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:simplejobscript:simplejobscript:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:simplejobscript:simplejobscript:*:*:*:*:*:*:*:*range: <=1.66
- (no CPE)
- Range: 1.66
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/46612nvdExploitVDB Entry
- www.vulncheck.com/advisories/simple-job-script-sql-injection-via-get-job-applications-ajaxphpnvdBroken Link
News mentions
0No linked articles in our index yet.