Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET parameter. Attackers can send crafted requests to news_details.php, jobs_details.php, or job_cmp_details.php with malicious 'id' values using GROUP BY and CASE statements to extract sensitive database information.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zeeways:jobsite_cms:-:*:*:*:*:*:*:* |
Wed, 15 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zeeways jobsite Cms
|
|
| CPEs | cpe:2.3:a:zeeways:jobsite_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zeeways jobsite Cms
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zeeways
Zeeways zeejobsite |
|
| Vendors & Products |
Zeeways
Zeeways zeejobsite |
Tue, 24 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET parameter. Attackers can send crafted requests to news_details.php, jobs_details.php, or job_cmp_details.php with malicious 'id' values using GROUP BY and CASE statements to extract sensitive database information. | |
| Title | Zeeways Jobsite CMS Lastest SQL Injection via id Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-24T11:27:09.305Z
Updated: 2026-03-24T17:53:55.551Z
Reserved: 2026-03-24T11:03:11.186Z
Link: CVE-2019-25636
Updated: 2026-03-24T17:53:52.671Z
Status : Analyzed
Published: 2026-03-24T12:16:04.400
Modified: 2026-04-15T16:10:09.500
Link: CVE-2019-25636
No data.