WebMO Job Manager Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in WebMO Job Manager version 20.0. This issue allows remote attackers to inject malicious scripts into search parameters. The vulnerability resides in the filterSearch and filterSearchType parameters of the jobmgr.cgi file. Exploitation of this vulnerability could lead to session hijacking and external redirects.

Impact

Exploitation of this vulnerability allows for session hijacking and non-persistent phishing attacks, as well as external redirects to malicious sources.

Reproduction

The vulnerability can be reproduced by sending a GET request to the jobmgr.cgi file with the filterSearch parameter containing the injected script, such as an alert script. The filterSearchType parameter can be left empty or set to one of the predefined options.

Added: Feb 1, 2026, 1:24 PM
Updated: Feb 1, 2026, 1:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.5
remediation
0.0
relevance
2.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.