What the vulnerability does
01Description
Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through 2.0.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through 2.0.0.
Explanation of Vulnerability in Simple Terms
JS Job Manager through version 2.0.0 fails to properly check user permissions before allowing modifications to job listings. A logged-in user with low privileges can alter or delete job postings they should not have access to. The vulnerability does not expose sensitive data but allows unauthorized changes to site content.
What an attacker can do
Modify or delete job listings without proper authorization.
Potential impact on your site
Job postings can be altered or removed by unauthorized users, disrupting job board functionality.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities