Summary
Detail | |||
---|---|---|---|
Vendor | Wp-Jobmanager | First view | 2017-10-19 |
Product | Job Manager | Last view | 2021-10-15 |
Version | Type | ||
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:a:wp-jobmanager:job_manager:*:*:*:*:*:wordpress:*:* | 3 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
4.8 | 2021-10-15 | CVE-2021-39336 | The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/admin-jobs.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 0.7.25. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled. |
6.1 | 2019-08-13 | CVE-2012-6713 | The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues. |
7.5 | 2017-10-19 | CVE-2015-6668 | The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
66% (2) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
33% (1) | CWE-200 | Information Exposure |