Vulnerability Description
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://extensions.joomla.org/extension/js-jobs/
- https://www.exploit-db.com/exploits/44492
- https://www.joomsky.com
- https://www.vulncheck.com/advisories/joomla-component-js-jobs-cross-site-request
FAQ
What is CVE-2018-25327?
CVE-2018-25327 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML...
How severe is CVE-2018-25327?
CVE-2018-25327 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25327?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.