[MAVEN:GHSA-4J2P-X79M-JCJ8] XXL-JOB vulnerable to Cross-site Scripting

Severity Moderate
Affected Packages 1
CVEs 1

XXL-JOB (com.xuxueli:xxl-job) versions 2.4.0 and earlier are vulnerable to cross-site scripting (XSS). An HTML uploaded payload can be executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

Package Affected Version
pkg:maven/com.xuxueli/xxl-job <= 2.4.0
ID
MAVEN:GHSA-4J2P-X79M-JCJ8
Severity
moderate
URL
https://github.com/advisories/GHSA-4j2p-x79m-jcj8
Published
2023-04-10T06:30:16
(17 months ago)
Modified
2023-04-18T14:53:30
(17 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.xuxueli/xxl-job com.xuxueli xxl-job <= 2.4.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...