Vulnerabilities
Vulnerable Software
Xuxueli:  >> Xxl-Job  >> 2.3.0  Security Vulnerabilities
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.
CVSS Score
3.5
EPSS Score
0.001
Published
2024-04-06
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
CVSS Score
8.8
EPSS Score
0.001
Published
2024-02-08
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-04-10
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-03-21
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
CVSS Score
8.8
EPSS Score
0.18
Published
2022-11-17
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
CVSS Score
8.8
EPSS Score
0.09
Published
2022-08-19
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
CVSS Score
5.4
EPSS Score
0.003
Published
2022-06-03
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.
CVSS Score
8.8
EPSS Score
0.001
Published
2022-05-23


Contact Us

Shodan ® - All rights reserved