216.73.217.22

CVE-2018-25327

· Published 17/05/2026 13:16 · Modified 18/05/2026 17:28

Labels: CVE-2018-25327 2026-05-17CVE-2018-25327CWE-352[email protected]

Essential information

Published
17/05/2026 13:16
Modified
18/05/2026 17:28
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
joomla / component js jobs cpe:2.3:a:joomla:component_js_jobs:1.2.0:*:*:*:*:*:*:*

References