CVE-2019-25502
MEDIUMsimplejobscript < 1.66 - Unauthenticated Stored Cross-Site Scripting via Job Type Value Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25502. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter.
Description
Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Simple Job Script. It includes functional payloads for SQLi via POST parameters and an XSS payload via a GET parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N