CVE-2022-1170CWE-79

CVE-2022-1170: vulnerability in Noo JobMonster

JobMonster < 4.5.2.9 - Unauthenticated Reflected Cross-Site Scripting

Published · Updated

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.8%
exploitation probability
1.8%top 22% of all CVEs
observed exploitation
nono source reports it
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
Affected products
Unknown · Noo JobMonster