CVE-2023-48087
- EPSS 0.05%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
CVE-2020-24922
- EPSS 1.35%
- Veröffentlicht 11.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:12
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
CVE-2023-33779
- EPSS 0.09%
- Veröffentlicht 26.05.2023 17:15:18
- Zuletzt bearbeitet 14.01.2025 20:15:27
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
CVE-2023-26120
- EPSS 0.12%
- Veröffentlicht 10.04.2023 05:15:07
- Zuletzt bearbeitet 07.02.2025 21:15:11
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
CVE-2023-27087
- EPSS 0.07%
- Veröffentlicht 21.03.2023 19:15:11
- Zuletzt bearbeitet 26.02.2025 19:15:17
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.
CVE-2023-0674
- EPSS 0.05%
- Veröffentlicht 04.02.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:36
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site reques...
CVE-2022-43183
- EPSS 19.87%
- Veröffentlicht 17.11.2022 21:15:15
- Zuletzt bearbeitet 29.04.2025 16:15:26
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.
CVE-2022-40929
- EPSS 0.37%
- Veröffentlicht 28.09.2022 18:15:09
- Zuletzt bearbeitet 21.05.2025 15:16:01
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
CVE-2022-36157
- EPSS 19.48%
- Veröffentlicht 19.08.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:30
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
CVE-2022-29770
- EPSS 0.23%
- Veröffentlicht 03.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:59:39
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.