What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.
Explanation of Vulnerability in Simple Terms
Simple Job Board through version 2.10.6 contains a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unwanted actions on behalf of site visitors. An attacker can craft a malicious link or page that, when visited by a logged-in user, triggers unintended changes to job board data or settings. The vulnerability requires user interaction but does not require authentication.
What an attacker can do
Perform unwanted actions on the job board (create, modify, or delete jobs) on behalf of a logged-in user.
Potential impact on your site
Job listings and board settings can be altered or deleted without the site owner's knowledge or consent.
Conditions required to exploit
A site visitor must click a malicious link or visit an attacker-controlled page while logged into the job board.
Key dates
External resources
Related vulnerabilities