Security Advisory

CVE-2019-25502

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-04 17:15:49
Last updated 2026-05-24 01:36:51
Assigner VulnCheck
State PUBLISHED

Description

Simple Job Script contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the job_type_value parameter in the jobs endpoint. Attackers can craft requests with SVG payload injection to execute arbitrary JavaScript in victim browsers and steal session cookies or perform unauthorized actions.