Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6828 | Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, and `wpjb-membership` modules. Remote attackers are able to inject malicious script code to hijack admin session credentials via the backend, or to manipulate the backend on client-side performed requests. The attack vector is non-persistent and the request method to inject is GET. The attacker does not need a privileged user account to perform a successful exploitation. |
| Link | Providers |
|---|---|
| https://www.vulnerability-lab.com/get_content.php?id=1941 |
|
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T00:25:48.080Z
Reserved: 2017-10-15T00:00:00.000Z
Link: CVE-2017-15375
No data.
Status : Modified
Published: 2017-10-16T04:29:00.407
Modified: 2026-06-17T01:07:43.310
Link: CVE-2017-15375
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD