← Vulnerability feed

Vulnerability record · CVE-2019-25502 · published 4 March 2026

CVE-2019-25502: Simplejobscript cross-site scripting vulnerability

Simplejobscript · Simplejobscript

Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.

5.1 CVSS 4.0 Medium EPSS 0.25% · top 85.2% CWE-79 · Cross-site scripting
5.1CVSS 4.0 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-25502 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8645Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. …EPSS 1.8%9.8CVE-2020-8440Simplejobscript unrestricted file upload vulnerabilitycontrollers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a r…EPSS 2.8%9.8CVE-2020-7229Simplejobscript sql injection vulnerabilityAn issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landin…EPSS 1.5%8.8CVE-2019-25498Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.37%8.8CVE-2019-25499Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.45%8.8CVE-2019-25500Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …EPSS 0.29%8.8CVE-2019-25501Simplejobscript sql injection vulnerabilitySimple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting malicious SQL code throug…EPSS 0.34%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2019-25502), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.