CVE-2022-1170
MEDIUMNuclei
JobMonster < 4.5.2.9 - Unauthenticated Reflected Cross-Site Scripting
Record summary
CVE-2022-1170 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Noo JobMonster | CVE List | 4.5.2.9 to < 4.5.2.9 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2022-1170Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2022-1170Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMJobMonster < 4.5.2.9 - Cross-Site ScriptingCVSS 6.1
In the theme JobMonster < 4.5.2.9 there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
Impact
Attackers can inject malicious JavaScript via XSS in the search form, potentially stealing user session cookies or performing unauthorized actions.
Remediation
Upgrade to JobMonster theme version 4.5.2.9 or later.
WeaknessesCWE-79
AuthorsAkincibor, ritikchaddha
Template tagscvecve2022wpscanwpwp-themewordpressxssjobmonsternoothemevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nootheme:jobmonster:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/themes/noo-jobmonster
FOFA: body=/wp-content/themes/noo-jobmonster
https://wpscan.com/vulnerability/2ecb18e6-b575-4a20-bd31-94d24f1d1efc https://nvd.nist.gov/vuln/detail/CVE-2022-1170 https://themeforest.net/item/jobmonster-job-board-wordpress-theme/10965446
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1170 themeforest.net
https://themeforest.net/item/jobmonster-job-board-wordpress-theme/10965446 wpscan.com
https://wpscan.com/vulnerability/2ecb18e6-b575-4a20-bd31-94d24f1d1efc