name:Simple Job Board < 2.9.4 - Authenticated Path Traversal Leading to Arbitrary File Download
author:cckuailong
severity:high
description:The plugin does not validate the sjb_file parameter when viewing a resume, allowing authenticated user with the download_resume capability (such as HR users) to download arbitrary files from the web-server via a path traversal attack.