Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.

Project Subscriptions

Vendors Products
Niteosoft Subscribe
Simple Job Script Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Niteosoft
Niteosoft simple Job Script
Vendors & Products Niteosoft
Niteosoft simple Job Script

Wed, 04 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.
Title Simple Job Script Cross-Site Scripting via job_type_value Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-04T17:15:49.050Z

Reserved: 2026-03-04T16:55:18.856Z

Link: CVE-2019-25502

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-04T18:16:08.830

Modified: 2026-03-04T18:16:08.830

Link: CVE-2019-25502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-05T09:06:47Z

Weaknesses