WebMO Job Manager Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in WebMO Job Manager version 20.0. This issue allows remote attackers to inject malicious scripts into search parameters. The vulnerability resides in the filterSearch and filterSearchType parameters of the jobmgr.cgi file. Exploitation of this vulnerability could lead to session hijacking and external redirects.
Impact
Exploitation of this vulnerability allows for session hijacking and non-persistent phishing attacks, as well as external redirects to malicious sources.
Reproduction
The vulnerability can be reproduced by sending a GET request to the jobmgr.cgi file with the filterSearch parameter containing the injected script, such as an alert script. The filterSearchType parameter can be left empty or set to one of the predefined options.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
