CVE-2019-25504:
SQL injection vulnerability in NCrypted Jobgator allows unauthenticated attackers to manipulate database queries via the experience parameter in the agents Find-Jobs endpoint.
Score
A numerical rating that indicates how dangerous this vulnerability is.
8.2High- Published Date:Mar 4, 2026
- CISA KEV Date:*No Data*
- Industries Affected:20
Exploitability
- Score:3.9
- Attack Vector:NETWORK
- Attack Complexity:LOW
- Privileges Required:NONE
- User Interaction:NONE
- Scope:UNCHANGED
Impact
- Score:4.2
- Confidentiality Impact:HIGH
- Integrity Impact:LOW
- Availability Impact:NONE
Description Preview
SQL injection vulnerability in NCrypted Jobgator allows unauthenticated attackers to manipulate database queries via the experience parameter in the agents Find-Jobs endpoint.
Overview
The vulnerability in NCrypted Jobgator is classified as a high-severity issue with a CVSS v3.1 base score of 8.2 and a CVSS v4.0 base score of 8.8. It requires no user interaction or special privileges to exploit, making it particularly dangerous. The primary impact is on data confidentiality, with a high potential for unauthorized information disclosure. There is also a low impact on data integrity, suggesting possible minor alterations to the database. The vulnerability does not affect system availability.
Remediation
- To address this vulnerability, administrators should implement the following measures:
- 1. Apply input validation and sanitization on the experience parameter and all user inputs.
- 2. Utilize prepared statements or parameterized queries instead of direct SQL string concatenation.
- 3. Implement least privilege database access for the application.
- 4. Regularly update and patch the NCrypted Jobgator software to the latest version.
- 5. Employ a web application firewall (WAF) to help detect and block SQL injection attempts.
- 6. Conduct a thorough security audit of the application to identify and address any similar vulnerabilities.
- 7. Implement proper error handling to prevent information leakage through error messages.
References
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.