Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.
History

Wed, 04 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.
Title Simple Job Script Cross-Site Scripting via job_type_value Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-04T17:15:49.050Z

Reserved: 2026-03-04T16:55:18.856Z

Link: CVE-2019-25502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-04T18:16:08.830

Modified: 2026-03-04T18:16:08.830

Link: CVE-2019-25502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.