Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simplejobscript
Simplejobscript simplejobscript |
|
| CPEs | cpe:2.3:a:simplejobscript:simplejobscript:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Simplejobscript
Simplejobscript simplejobscript |
Thu, 05 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Niteosoft
Niteosoft simple Job Script |
|
| Vendors & Products |
Niteosoft
Niteosoft simple Job Script |
Wed, 04 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions. | |
| Title | Simple Job Script Cross-Site Scripting via job_type_value Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:04:49.352Z
Reserved: 2026-03-04T16:55:18.856Z
Link: CVE-2019-25502
Updated: 2026-03-05T16:02:33.312Z
Status : Analyzed
Published: 2026-03-04T18:16:08.830
Modified: 2026-03-05T22:16:05.303
Link: CVE-2019-25502
No data.
OpenCVE Enrichment
Updated: 2026-03-05T09:06:47Z