Joomla! Component JS Jobs Cross-Site Request Forgery Vulnerability

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in the Joomla! component JS Jobs, version 1.2.0. This vulnerability allows attackers to perform state-changing actions without proper token validation. By crafting malicious HTML forms that target administrative endpoints, such as 'job.jobenforcedelete', attackers can delete job entries or alter component settings. This exploitation occurs when administrators visit pages controlled by the attacker.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of job entries or modification of component settings on behalf of an administrator.

Reproduction

To reproduce this vulnerability, create a malicious HTML form that includes the necessary hidden input fields to target an administrative endpoint, such as 'job.jobenforcedelete'. Once the form is prepared, it can be submitted automatically when an administrator visits the page, performing the desired state-changing action without their consent.

Remediation

Users are advised to update to the latest version of the JS Jobs component.

Added: May 17, 2026, 1:27 PM
Updated: May 17, 2026, 1:27 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
7.9
remediation
7.7
relevance
8.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.