Xuxueli

Xxl-job

24 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Published 15.11.2023 15:15:07
  • Last modified 21.11.2024 08:31:05

xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.

Exploit
  • EPSS 1.35%
  • Published 11.08.2023 14:15:10
  • Last modified 21.11.2024 05:16:12

Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

Exploit
  • EPSS 0.09%
  • Published 26.05.2023 17:15:18
  • Last modified 14.01.2025 20:15:27

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.

Exploit
  • EPSS 0.12%
  • Published 10.04.2023 05:15:07
  • Last modified 07.02.2025 21:15:11

This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

Exploit
  • EPSS 0.07%
  • Published 21.03.2023 19:15:11
  • Last modified 26.02.2025 19:15:17

Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

Exploit
  • EPSS 0.05%
  • Published 04.02.2023 08:15:08
  • Last modified 21.11.2024 07:37:36

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site reques...

Exploit
  • EPSS 19.87%
  • Published 17.11.2022 21:15:15
  • Last modified 29.04.2025 16:15:26

XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

Exploit
  • EPSS 0.37%
  • Published 28.09.2022 18:15:09
  • Last modified 21.05.2025 15:16:01

XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

  • EPSS 19.48%
  • Published 19.08.2022 22:15:09
  • Last modified 21.11.2024 07:12:30

XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.

Exploit
  • EPSS 0.23%
  • Published 03.06.2022 21:15:07
  • Last modified 21.11.2024 06:59:39

XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.