vendor:
JS Jobs
by:
Sureshbabu Narvaneni
5.4
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: JS Jobs
Affected Version From: 1.2.0
Affected Version To: 1.2.0
Patch Exists: YES
Related CWE: CVE-2018-9183
CPE: a:joomsky:js_jobs:1.2.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win7 Enterprise x86/Kali Linux 4.12 i686
2018
Joomla! Component JS Jobs 1.2.0 – Cross Site Scripting
JS Jobs 1.2.0 is missing validation on URL inserted by attacker/employer while creating company entry. An attacker can create a company entry by logging in as Employer and paste a payload in place of URL field such as javascript:alert(1) or data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K
Mitigation:
Upgrade to latest release.