Executive brief
Js Jobs is a recruitment and job board extension for the Joomla content management system. A security flaw in version 1.2.0 allows attackers to trick an administrator into performing unintended actions, such as deleting job listings or changing system settings, by simply visiting a malicious website. This could lead to unauthorized data loss or disruption of the job board service.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the JoomSky Js Jobs component (version 1.2.0 and earlier) for Joomla. The application fails to implement or validate anti-CSRF tokens for state-changing administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by an authenticated administrator, triggers hidden requests to endpoints such as 'job.jobenforcedelete'. Successful exploitation allows the attacker to delete job entries or modify component configurations. The vulnerability was addressed in version 1.2.1.
Affected products
- JoomSky Js Jobs 1.2.0 and earlier
Timeline
- 2018-04-17: disclosed: Initial discovery and exploit publication by Sureshbabu Narvaneni
- 2018-04-18: other: Exploit-DB entry published
- 2026-05-17: advisory: CVE record published/updated in NVD