Executive brief
CodeAstro Online Job Portal is a web application used to manage job listings and recruitment. A security vulnerability in the administrative job deletion feature allows an attacker to manipulate database queries. This could lead to unauthorized access to sensitive information, data deletion, or full control over the application's database without requiring any login credentials.
Technical details
A SQL injection vulnerability exists in CodeAstro Online Job Portal 1.0 within the '/admin/jobs-admins/delete-jobs.php' file. The root cause is the failure to sanitize or validate the 'id' GET parameter before using it in a SQL query. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests containing SQL payloads (such as boolean-based blind, error-based, or time-based blind techniques). Successful exploitation allows for unauthorized database access, data exfiltration, and potential system compromise. A public exploit (PoC) using sqlmap has been disclosed.
Affected products
- CodeAstro Online Job Portal Project 1.0
Timeline
- 2026-03-21: disclosed: Public issue report on GitHub
- 2026-06-01: advisory: CVE published and NVD record created