Vulnerability Description
Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simplejobscript | Simplejobscript | <= 1.66 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/46612ExploitVDB Entry
- https://www.vulncheck.com/advisories/simple-job-script-cross-site-scripting-via-Third Party Advisory
FAQ
What is CVE-2019-25502?
CVE-2019-25502 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Att...
How severe is CVE-2019-25502?
CVE-2019-25502 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25502?
Check the references section above for vendor advisories and patch information. Affected products include: Simplejobscript Simplejobscript.