S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-32007 Scanner

Detects 'SQL Injection' vulnerability in Complete Online Job Search System affects v. 1.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-32007
7.2
CVSS

Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/admin/company/index.php?view=edit&id=.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Complete Online Job Search System (COJSS) is an all-in-one job search software designed to simplify the recruitment process. It is widely used by organizations both large and small to manage their hiring activities on a single platform. COJSS provides a user-friendly interface for recruiters to create job postings, search for candidates, and manage applications. One of the key features of the software is its ability to automate recruitment tasks, thereby saving recruiters time and effort.

CVE-2022-32007 is a vulnerability that has been detected in the COJSS software. This vulnerability enables hackers to execute SQL injection attacks through the /eris/admin/company/index.php?view=edit&id= endpoint. SQL injection attacks enable attackers to inject malicious SQL code into a webpage input field, such as a login or search bar. This code can then be executed within the website's database, which can allow the attacker to obtain sensitive data or even take control of the website.

If exploited, this vulnerability can lead to devastating consequences for an organization. Hackers can easily gain unauthorized access to the organization's databases, allowing them to steal sensitive data such as user credentials, financial records, or any other confidential information. Moreover, the attacker can use this access to carry out other nefarious activities like executing malware, ransomware, or even a full website takeover.

By using the pro features of the s4e.io platform, anyone can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive database of security vulnerabilities along with expert analysis and recommendations to prevent them. Additionally, users can receive alerts for newly discovered vulnerabilities that may impact their digital assets and can receive remediation advice. With s4e.io, organizations can stay ahead of emerging security threats and keep their digital assets safe and secure.

 

REFERENCES

Solution Advice

In order to protect against the CVE-2022-32007 vulnerability, the following precautions can be taken:

  • Regularly update the software to the latest version.
  • Use web application firewalls to detect and prevent malicious SQL injection attempts.
  • Implement proper input validation to filter out any malicious input from the website.
  • Utilize security software to scan and monitor for any vulnerabilities in the website.
  • Follow best coding practices and guidelines for website development to mitigate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.