vendor:
Job Listing Script
by:
HackXBack
7,5
CVSS
HIGH
Cross Site Request Forgery & Multiple Cross Site Scripting
352, 79
CWE
Product Name: Job Listing Script
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Job Listing Script – Multiple Vulnerabilties
Cross Site Request Forgery (CSRF) vulnerability in the Job Listing Script allows remote attackers to hijack the authentication of administrators for requests that change the username and password. Multiple Cross Site Scripting (XSS) vulnerabilities in the Job Listing Script allow remote attackers to inject arbitrary web script or HTML via the category_title parameter to index.php.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update to the latest version of the Job Listing Script.