CVE-2022-1170: JobMonster < 4.5.2.9 - Unauthenticated Reflected Cross-Site Scripting
Published Apr 4, 2022
·Updated
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
Affected Software
1 affected component
NooTheme Jobmonster Wordpress<4.5.2.9
Event History
Apr 4, 2022
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1170?
CVE-2022-1170 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-1170?
To fix CVE-2022-1170, update the Noo JobMonster theme to version 4.5.2.9 or later.
3
What are the potential consequences of CVE-2022-1170?
Exploitation of CVE-2022-1170 could allow attackers to execute arbitrary JavaScript code in the context of the affected site.
4
Which versions of Noo JobMonster are affected by CVE-2022-1170?
Noo JobMonster versions prior to 4.5.2.9 are affected by CVE-2022-1170.
5
Can CVE-2022-1170 be exploited through the search form?
Yes, CVE-2022-1170 can be exploited through unsanitized input provided via GET requests in the search form.