vendor:
JS Jobs
by:
Sureshbabu Narvaneni
7.5
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: JS Jobs
Affected Version From: 1.2.0
Affected Version To: 1.2.1
Patch Exists: YES
Related CWE: NA
CPE: a:joomsky:js_jobs
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 Enterprise x86/Kali Linux 4.12 i686
2018
Joomla! Component Js Jobs – Multiple Cross Site Request Forgery Vulnerabilities
The state changing actions in JS Jobs before 1.2.1 not having any random token validation which results in Cross Site Request Forgery Vulnerability.
Mitigation:
Implement random token validation for state changing actions.