Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information.
History

Wed, 04 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information.
Title Simple Job Script SQL Injection via searched Endpoint
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-03-04T17:15:45.434Z

Updated: 2026-03-04T17:15:45.434Z

Reserved: 2026-03-04T16:47:52.167Z

Link: CVE-2019-25498

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-04T18:16:08.020

Modified: 2026-03-04T18:16:08.020

Link: CVE-2019-25498

cve-icon Redhat

No data.