Record summary

CVE-2022-1170 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Noo JobMonster

CVE List4.5.2.9 to < 4.5.2.9affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-1170Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 465 B

GitHub

PoC details
GitHubCVE-2022-1170Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 465 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMJobMonster < 4.5.2.9 - Cross-Site ScriptingCVSS 6.1

In the theme JobMonster < 4.5.2.9 there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

Impact

Attackers can inject malicious JavaScript via XSS in the search form, potentially stealing user session cookies or performing unauthorized actions.

Remediation

Upgrade to JobMonster theme version 4.5.2.9 or later.

WeaknessesCWE-79
AuthorsAkincibor, ritikchaddha
Template tagscvecve2022wpscanwpwp-themewordpressxssjobmonsternoothemevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nootheme:jobmonster:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/themes/noo-jobmonster
FOFA: body=/wp-content/themes/noo-jobmonster

Source: ProjectDiscovery

References

3