PT-2017-14033 · Wpjobboard · Wpjobboard

Benjamin Kunz Mejri

·

Published

2017-10-16

·

Updated

2017-11-06

·

CVE-2017-15375

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WpJobBoard version 4.5.1
Description The issue concerns multiple client-side cross-site scripting vulnerabilities. These vulnerabilities are located in the query and id parameters of the wpjb-email, wpjb-job, wpjb-application, and wpjb-membership modules. Remote attackers can inject malicious script code to hijack admin session credentials via the backend or manipulate the backend on client-side performed requests. The attack vector is non-persistent, and the request method to inject is GET. No privileged user account is needed for a successful exploitation.
Recommendations For WpJobBoard version 4.5.1, consider disabling the wpjb-email, wpjb-job, wpjb-application, and wpjb-membership modules until a patch is available. Avoid using the query and id parameters in these modules to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15375

Affected Products

Wpjobboard