CVE-2020-23814: XSS
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-23814?
The severity of CVE-2020-23814 is medium (6.1).
What is the CWE category of CVE-2020-23814?
CVE-2020-23814 belongs to CWE category 79 (Cross-Site Scripting).
How do I fix the XSS vulnerabilities in xxl-job v2.2.0?
To fix the XSS vulnerabilities in xxl-job v2.2.0, update to a version that addresses the issue, if available, or apply any patches or fixes provided by the vendor.
Where can I find more information about CVE-2020-23814?
More information about CVE-2020-23814 can be found at the following references: [https://github.com/xuxueli/xxl-job/issues/1866](https://github.com/xuxueli/xxl-job/issues/1866) and [https://www.ccsq8.com/issues.html](https://www.ccsq8.com/issues.html).
What are the affected software versions of CVE-2020-23814?
CVE-2020-23814 affects version 2.2.0 of xxl-job.