Vulnerabilities
Vulnerable Software
Xuxueli:  >> Xxl-Job  Security Vulnerabilities
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-02-04
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
CVSS Score
8.8
EPSS Score
0.18
Published
2022-11-17
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
CVSS Score
9.8
EPSS Score
0.002
Published
2022-09-28
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
CVSS Score
8.8
EPSS Score
0.09
Published
2022-08-19
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
CVSS Score
5.4
EPSS Score
0.003
Published
2022-06-03
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
CVSS Score
8.8
EPSS Score
0.001
Published
2022-05-23
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
CVSS Score
6.1
EPSS Score
0.002
Published
2020-12-27
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-09-03
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-09-03


Contact Us

Shodan ® - All rights reserved