Description
WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers to inject malicious script code. Attackers can exploit the filterSearch and filterSearchType parameters to perform non-persistent attacks including session hijacking and external redirects.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
20.0
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2270 (Vulnerability Lab Advisory)
www.webmo.net (Product Homepage)
www.vulncheck.com/...ss-site-scripting-via-search-parameters (VulnCheck Advisory: WebMO Job Manager 20.0 Cross-Site Scripting via Search Parameters)