The Naukri Clone Script Project maintains a single, application-level job-portal product, which is a web-facing recruitment platform script that sits on the attack surface of deployments using it. Observed vulnerabilities cluster around web-application input-handling weaknesses, including cross-site scripting, improper input validation, and unrestricted file uploads, reflecting the risks inherent to user-facing portal software that processes job postings and applicant data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Naukri Clone Script Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15185MEDIUM PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "C | Aug 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-11514HIGH PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php. | May 28, 2018 | 8.8 | 22 | NO | NO |
CVE-2018-15184MEDIUM PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795. | Aug 9, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-6795MEDIUM PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field. | Feb 7, 2018 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Naukri Clone Script Project.
Media articles that mention a CVE ID that affects a product developed by Naukri Clone Script Project — matched by CVE ID, not by vendor name.