Alternate version:

  • CanadaPlus@lemmy.sdf.org
    link
    fedilink
    arrow-up
    4
    ·
    1 month ago

    So does that imply they already knew the candidate they were hiring, and were just checking if this is the guy?

    • ulterno
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      Yeah, this seems like an exploit for those cases.

    • MadhuGururajan
      link
      fedilink
      English
      arrow-up
      1
      ·
      24 days ago

      No the interviewer is personification of the naive backend that checks only that a specific row is present in the DB, or that’s how I read it.

      • CanadaPlus@lemmy.sdf.org
        link
        fedilink
        arrow-up
        1
        ·
        24 days ago

        So I guess the interview is handled by a non-vulnerable intermediate process, which adds the hire to the the main table of employees when at some point in a successful interview, and then calls a notification process that just searches it?

        • MadhuGururajan
          link
          fedilink
          English
          arrow-up
          2
          ·
          24 days ago

          yeah something like “if new candidate in employee DB == hired”