First published: Thu Sep 03 2020(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
xuxueli xxl-job | =2.2.0 | |
maven/com.xuxueli:xxl-job | <2.3.0 | 2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-23814 is medium (6.1).
CVE-2020-23814 belongs to CWE category 79 (Cross-Site Scripting).
To fix the XSS vulnerabilities in xxl-job v2.2.0, update to a version that addresses the issue, if available, or apply any patches or fixes provided by the vendor.
More information about CVE-2020-23814 can be found at the following references: [https://github.com/xuxueli/xxl-job/issues/1866](https://github.com/xuxueli/xxl-job/issues/1866) and [https://www.ccsq8.com/issues.html](https://www.ccsq8.com/issues.html).
CVE-2020-23814 affects version 2.2.0 of xxl-job.