CVE-2024-3366
- EPSS 0.95%
- Veröffentlicht 06.04.2024 11:15:08
- Zuletzt bearbeitet 18.07.2025 18:49:58
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads ...
CVE-2024-24113
- EPSS 0.57%
- Veröffentlicht 08.02.2024 13:15:09
- Zuletzt bearbeitet 15.05.2025 20:15:45
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.
CVE-2023-48088
- EPSS 0.4%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage.
CVE-2023-48089
- EPSS 1.26%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
CVE-2023-48087
- EPSS 0.36%
- Veröffentlicht 15.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:05
xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat.
CVE-2020-24922
- EPSS 0.44%
- Veröffentlicht 11.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:16:12
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.
CVE-2023-33779
- EPSS 1.13%
- Veröffentlicht 26.05.2023 17:15:18
- Zuletzt bearbeitet 14.01.2025 20:15:27
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.
CVE-2023-26120
- EPSS 0.46%
- Veröffentlicht 10.04.2023 05:15:07
- Zuletzt bearbeitet 07.02.2025 21:15:11
This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.
CVE-2023-27087
- EPSS 0.64%
- Veröffentlicht 21.03.2023 19:15:11
- Zuletzt bearbeitet 26.02.2025 19:15:17
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.
CVE-2023-0674
- EPSS 0.39%
- Veröffentlicht 04.02.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 07:37:36
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site reques...