The Company's Recruitment Management System in id2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309''1309 and 39476597' or '2917''2923 were each submitted in the id parameter. These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.
Publication date: Wed, 17 Nov 2021 18:15:00 +0000