CVE-2024-42681
- EPSS 0.89%
- Veröffentlicht 15.08.2024 17:15:18
- Zuletzt bearbeitet 19.08.2024 19:35:08
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
CVE-2024-3366
- EPSS 0.95%
- Veröffentlicht 06.04.2024 11:15:08
- Zuletzt bearbeitet 18.07.2025 18:49:58
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads ...
CVE-2024-24113
- EPSS 0.57%
- Veröffentlicht 08.02.2024 13:15:09
- Zuletzt bearbeitet 15.05.2025 20:15:45
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
CVE-2023-48088
- EPSS 0.4%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
CVE-2023-48089
- EPSS 1.26%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CVE-2023-48087
- EPSS 0.36%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
CVE-2020-24922
- EPSS 0.5%
- Veröffentlicht 11.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:12
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
CVE-2023-33779
- EPSS 0.94%
- Veröffentlicht 26.05.2023 17:15:18
- Zuletzt bearbeitet 09.07.2026 01:18:25
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
CVE-2023-26120
- EPSS 0.46%
- Veröffentlicht 10.04.2023 05:15:07
- Zuletzt bearbeitet 07.02.2025 21:15:11
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
CVE-2023-27087
- EPSS 0.64%
- Veröffentlicht 21.03.2023 19:15:11
- Zuletzt bearbeitet 26.02.2025 19:15:17
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.